📦 Zbzcms

by Zbzcms

🔍 What is Zbzcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-27126

CRITICAL CVSS 9.8 Apr 10, 2022

CVE-2022-27126 is a SQL injection vulnerability in zbzcms v1.0 that allows attackers to execute arbitrary SQL commands via the art parameter at /include/make.php. This affects all installations of zbz...

CVE-2022-27128

CRITICAL CVSS 9.8 Apr 10, 2022

CVE-2022-27128 is an authentication bypass vulnerability in zbzcms v1.0 that allows unauthenticated attackers to add administrator accounts via the /admin/run_ajax.php endpoint. This affects all insta...

CVE-2022-27131

CRITICAL CVSS 9.8 Apr 10, 2022

This vulnerability allows attackers to upload arbitrary PHP files to zbzcms v1.0 through the /zbzedit/php/zbz.php endpoint. Successful exploitation enables remote code execution, potentially giving at...