Zzzcms Zzzphp
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Zzzcms Zzzphp.
By the Year
In 2026 there have been 0 vulnerabilities in Zzzcms Zzzphp. Zzzphp did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 6.10 |
| 2022 | 1 | 9.80 |
| 2021 | 1 | 9.80 |
| 2020 | 1 | 9.80 |
| 2019 | 7 | 8.98 |
It may take a day or so for new Zzzphp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Zzzcms Zzzphp Security Vulnerabilities
zZzCMS v2.2.0 Open Redirect (before 2.2.0)
CVE-2023-45909
6.1 - Medium
- October 18, 2023
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
Open Redirect
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability
CVE-2022-23881
9.8 - Critical
- March 23, 2022
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
zzzcms zzzphp before 2.0.4
CVE-2021-32605
9.8 - Critical
- May 11, 2021
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
Shell injection
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2
CVE-2020-20298
9.8 - Critical
- December 18, 2020
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3
CVE-2019-17408
- October 14, 2019
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage
CVE-2019-16720
7.5 - High
- September 23, 2019
ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=catchimage, as demonstrated by uploading a .htaccess or .php5 file.
Unrestricted File Upload
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution
CVE-2019-16722
9.8 - Critical
- September 23, 2019
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
Improper Input Validation
ZZZCMS zzzphp v1.6.3
CVE-2019-10647
9.8 - Critical
- March 30, 2019
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of a lack of inc/zzz_file.php restrictions. For example, source%5B%5D=http%3A%2F%2F192.168.0.1%2Ftest.php can be used if the 192.168.0.1 web server sends the contents of a .php file (i.e., it does not interpret a .php file).
Unrestricted File Upload
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request
CVE-2019-9182
- February 26, 2019
There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by providing a filename in the file parameter, and providing file content in the filetext parameter.
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products
CVE-2019-9082
8.8 - High
- February 24, 2019
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Missing Authentication for Critical Function
An issue was discovered in ZZZCMS zzzphp V1.6.1
CVE-2019-9041
- February 23, 2019
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demonstrated by the if:assert substring.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Zzzcms Zzzphp or by Zzzcms? Click the Watch button to subscribe.