VendorsCSKAZAcszcms1.3.0
Vulnerabilities

CSKAZA CSZ CMS 1.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2023-34545
A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL.
Published 2023-08-09 · Modified
9.8EPSS 0.008
CVE-2023-6302
CSZCMS File Manager Page templates permission
Published 2023-11-27 · Modified
7.2EPSS 0.009
CVE-2023-41436
Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component.
Published 2023-09-15 · Modified
5.4EPSS 0.005
CVE-2023-6303
CSZCMS Site Settings Page cross site scripting
Published 2023-11-27 · Modified
4.8EPSS 0.006