📦 Zkeacms

by Zkea

🔍 What is Zkeacms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-52239

CRITICAL CVSS 9.8 Aug 4, 2025

CVE-2025-52239 is an arbitrary file upload vulnerability in ZKEACMS v4.1 that allows attackers to upload malicious files and execute arbitrary code on the server. This affects all systems running the ...

CVE-2020-20670

HIGH CVSS 8.8 Sep 13, 2021

This vulnerability allows attackers to upload arbitrary HTML files to the ZKEACMS admin media upload endpoint, which can lead to remote code execution. Attackers can craft malicious HTML files that ex...

CVE-2025-10766

MEDIUM CVSS 4.3 Sep 21, 2025

This CVE describes a path traversal vulnerability in SeriaWei ZKEACMS up to version 4.3. Attackers can manipulate the ID parameter in the Download function to access arbitrary files on the server. Org...

CVE-2025-10765

MEDIUM CVSS 4.7 Sep 21, 2025

This vulnerability allows remote attackers to perform server-side request forgery (SSRF) attacks against SeriaWei ZKEACMS installations up to version 4.3. Attackers can manipulate the CheckPage/Sugges...

CVE-2025-10764

MEDIUM CVSS 6.3 Sep 21, 2025

This vulnerability in SeriaWei ZKEACMS allows attackers to perform server-side request forgery (SSRF) attacks by manipulating the Data argument in the Edit function of the PendingTaskController. Attac...