VendorsZKEAzkeacmsall versions
Vulnerabilities

ZKEA Zkeacms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-52239
An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
Published 2025-08-04 · Modified
9.8EPSS 0.004
CVE-2020-20670
An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.
Published 2021-09-13 · Modified
8.8EPSS 0.017
CVE-2025-10764
SeriaWei ZKEACMS Event Action System PendingTaskController.cs Edit server-side request forgery
Published 2025-09-21 · Analyzed
8.8EPSS 0.004
CVE-2025-10471
ZKEACMS MediaController.cs Proxy server-side request forgery
Published 2025-09-15 · Analyzed
8.8EPSS 0.003
CVE-2025-10765
SeriaWei ZKEACMS SEOSuggestions ZKEACMS.SEOSuggestions.dll server-side request forgery
Published 2025-09-21 · Analyzed
7.2EPSS 0.004
CVE-2022-29362
A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.
Published 2022-05-25 · Modified
5.4EPSS 0.005
CVE-2025-10766
SeriaWei ZKEACMS EventViewerController.cs Download path traversal
Published 2025-09-21 · Analyzed
4.3EPSS 0.006