Home/Product/cszcms csz cms
Product

cszcms csz cms

36 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2021-47738
all versions
CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScrip
5.4MEDIUM
CVE-2021-47737
all versions
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message t
5.4MEDIUM
CVE-2024-58307
all versions
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated att
8.8HIGH
CVE-2025-63608
<= 1.3.0
A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in th
5.4MEDIUM
CVE-2025-29084
all versions
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in
6.5MEDIUM
CVE-2025-29083
all versions
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in
6.5MEDIUM
CVE-2024-27752
all versions
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword f
5.4MEDIUM
CVE-2024-27734
all versions
A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the S
6.1MEDIUM
CVE-2024-25414
all versions
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploadin
9.8CRITICAL
CVE-2023-6303
all versions
A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the file /admin/
2.4LOW
CVE-2023-6302
all versions
A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the
4.7MEDIUM
CVE-2023-41436
all versions
Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the
5.4MEDIUM
CVE-2023-41601
all versions
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary we
6.1MEDIUM
CVE-2023-39599
all versions
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to th
5.4MEDIUM
CVE-2023-38911
all versions
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to th
5.4MEDIUM
CVE-2023-38910
all versions
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a c
6.1MEDIUM
CVE-2020-36136
all versions
SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail paramet
7.5HIGH
CVE-2023-34545
all versions
A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search
9.8CRITICAL
CVE-2020-19786
all versions
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via craf
8.8HIGH
CVE-2022-28997
all versions
CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a
7.5HIGH
CVE-2022-27165
all versions
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
9.8CRITICAL
CVE-2022-27164
all versions
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
9.8CRITICAL
CVE-2022-27163
all versions
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
9.8CRITICAL
CVE-2022-27162
all versions
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
9.8CRITICAL
CVE-2022-27161
all versions
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
9.8CRITICAL
CVE-2021-43701
all versions
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via
6.5MEDIUM
CVE-2021-46377
all versions
There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
9.8CRITICAL
CVE-2020-21250
all versions
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
9.8CRITICAL
CVE-2021-37144
all versions
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input mig
9.1CRITICAL
CVE-2020-25392
all versions
A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafte
5.4MEDIUM
CVE-2020-25391
all versions
A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payl
5.4MEDIUM
CVE-2021-26776
all versions
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
5.4MEDIUM
CVE-2021-3224
all versions
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
5.4MEDIUM
CVE-2019-15524
all versions
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, whi
9.8CRITICAL
CVE-2019-13086
<= 1.2.2
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent
9.8CRITICAL
CVE-2019-7566
all versions
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
8.8HIGH
threatengine.sh