Zzzphp Zzzcms Zzzphp

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Zzzcms Zzzphp.

By the Year

In 2026 there have been 0 vulnerabilities in Zzzcms Zzzphp. Zzzphp did not have any published security vulnerabilities last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 1 6.10
2022 1 9.80
2021 1 9.80
2020 1 9.80
2019 7 8.98

It may take a day or so for new Zzzphp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Zzzcms Zzzphp Security Vulnerabilities

zZzCMS v2.2.0 Open Redirect (before 2.2.0)
CVE-2023-45909 6.1 - Medium - October 18, 2023

zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.

Open Redirect

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability
CVE-2022-23881 9.8 - Critical - March 23, 2022

ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

zzzcms zzzphp before 2.0.4
CVE-2021-32605 9.8 - Critical - May 11, 2021

zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.

Shell injection

Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2
CVE-2020-20298 9.8 - Critical - December 18, 2020

Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.

parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3
CVE-2019-17408 - October 14, 2019

parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage
CVE-2019-16720 7.5 - High - September 23, 2019

ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.

Unrestricted File Upload

ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution
CVE-2019-16722 9.8 - Critical - September 23, 2019

ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.

Improper Input Validation

ZZZCMS zzzphp v1.6.3
CVE-2019-10647 9.8 - Critical - March 30, 2019

ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).

Unrestricted File Upload

There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request
CVE-2019-9182 - February 26, 2019

There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products
CVE-2019-9082 8.8 - High - February 24, 2019

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Missing Authentication for Critical Function

An issue was discovered in ZZZCMS zzzphp V1.6.1
CVE-2019-9041 - February 23, 2019

An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Zzzcms Zzzphp or by Zzzcms? Click the Watch button to subscribe.

Zzzcms
Vendor

Zzzcms Zzzphp
Product

subscribe