VendorsCSZ CMScsz_cmsany version
Vulnerabilities

CSZ CMS Csz CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-13086
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Published 2019-06-30 · Modified
9.8EPSS 0.320
CVE-2025-63608
A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.
Published 2025-10-30 · Analyzed
5.4EPSS 0.002