VendorsJuzaWebcmsall versions
Vulnerabilities

JuzaWeb CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-6735
juzaweb CMS Import Page imports improper authorization
Published 2025-06-26 · Analyzed
8.8EPSS 0.005
CVE-2025-6736
juzaweb CMS Add New Themes Page install improper authorization
Published 2025-06-26 · Analyzed
8.8EPSS 0.005
CVE-2025-5424
juzaweb CMS Media Page media access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.005
CVE-2025-5425
juzaweb CMS Theme Editor Page default access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5421
juzaweb CMS Plugin Editor Page editor access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5423
juzaweb CMS General Setting Page general access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5426
juzaweb CMS Menu Page menus access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5427
juzaweb CMS Permalinks Page permalinks access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5428
juzaweb CMS Error Logs Page log-viewer access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2025-5429
juzaweb CMS Plugins Page install access control
Published 2025-06-02 · Analyzed
6.5EPSS 0.004
CVE-2023-46467
Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registration page.
Published 2023-10-28 · Modified
5.4EPSS 0.005
CVE-2025-5420
juzaweb CMS Profile Page upload cross site scripting
Published 2025-06-02 · Analyzed
5.4EPSS 0.003
CVE-2025-5422
juzaweb CMS Email Logs Page email access control
Published 2025-06-02 · Analyzed
5.3EPSS 0.005
CVE-2024-7551
juzaweb CMS Theme Editor default path traversal
Published 2024-08-06 · Analyzed
5.1EPSS 0.009
CVE-2023-46906
juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.
Published 2024-01-09 · Modified
4.9EPSS 0.007