← Back

Zzcms

zzcms

Vendor: Zzcms • 106 CVEs

CVEs (106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged f...Show more
An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leverag...Show more
An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
1Zzcms
1Zzcms
Jun 17, 2026
Mar 24, 2018
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for dat...Show more
An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock.Show less
1Zzcms
1Zzcms
Jun 17, 2026
Feb 24, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php.