VendorsCSZ CMScsz_cmsall versions
Vulnerabilities

CSZ CMS Csz CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Published 2019-06-30 · Modified
9.8EPSS 0.320
CVE-2019-15524
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a photo/upload/2019/ URI.
Published 2019-08-26 · Modified
9.8EPSS 0.031
CVE-2024-25414
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.
Published 2024-02-16 · Modified
9.8EPSS 0.016
CVE-2022-27161
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
Published 2022-04-12 · Modified
9.8EPSS 0.013
CVE-2020-21250
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
Published 2021-10-27 · Modified
9.8EPSS 0.012
CVE-2022-27163
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
Published 2022-04-12 · Modified
9.8EPSS 0.012
CVE-2022-27162
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
Published 2022-04-12 · Modified
9.8EPSS 0.011
CVE-2022-27164
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
Published 2022-04-12 · Modified
9.8EPSS 0.011
CVE-2022-27165
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
Published 2022-04-12 · Modified
9.8EPSS 0.011
CVE-2024-58307
CSZCMS 1.3.0 Authenticated SQL Injection via Members View Endpoint
Published 2025-12-11 · Analyzed
9.3EPSS 0.005
CVE-2021-37144
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.
Published 2021-07-29 · Modified
9.1EPSS 0.013
CVE-2020-19786
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
Published 2023-03-23 · Modified
8.8EPSS 0.008
CVE-2019-7566
CSZ CMS 1.1.8 has CSRF via admin/users/new/add.
Published 2019-02-07 · Modified
8.8EPSS 0.007
CVE-2021-43701
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.
Published 2022-03-29 · Modified
6.51 PoCEPSS 0.033
CVE-2025-29083
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Plugin_Manager.php file.
Published 2025-09-23 · Analyzed
6.5EPSS 0.004
CVE-2025-29084
SQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the Upgrade.php file.
Published 2025-09-23 · Analyzed
6.5EPSS 0.004
CVE-2023-38910
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
Published 2023-08-18 · Modified
6.1EPSS 0.005
CVE-2024-27734
A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted script to the Site Name fields of the Site Settings component.
Published 2024-03-01 · Analyzed
6.1EPSS 0.005
CVE-2023-41601
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.
Published 2023-09-06 · Modified
6.1EPSS 0.004
CVE-2024-27752
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.
Published 2024-04-19 · Analyzed
5.4EPSS 0.006
CVE-2021-3224
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
Published 2021-03-10 · Modified
5.4EPSS 0.005
CVE-2021-26776
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
Published 2021-03-11 · Modified
5.4EPSS 0.005
CVE-2023-39599
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.
Published 2023-08-22 · Modified
5.4EPSS 0.005
CVE-2023-38911
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.
Published 2023-08-18 · Modified
5.4EPSS 0.005
CVE-2020-25392
A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Article' field under the 'Article' plugin.
Published 2021-07-09 · Modified
5.4EPSS 0.005
CVE-2020-25391
A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module.
Published 2021-07-09 · Modified
5.4EPSS 0.005
CVE-2021-47738
CSZ CMS 1.2.7 Persistent Cross-Site Scripting via Private Messaging
Published 2025-12-23 · Modified
5.4EPSS 0.003
CVE-2021-47737
CSZ CMS 1.2.7 HTML Injection Vulnerability via Member Dashboard
Published 2025-12-23 · Analyzed
5.4EPSS 0.003
CVE-2025-63608
A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.
Published 2025-10-30 · Analyzed
5.4EPSS 0.002