Cskaza's vulnerability profile centers on a content-management system product that, despite limited product scope, receives disproportionate attention in the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through application-layer input-handling weaknesses such as SQL injection and cross-site scripting, alongside improper default permission configurations that reflect common CMS deployment challenges. Live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cskaza over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46377CRITICAL There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser | Jan 27, 2022 | 9.8 | 29 | NO | NO |
CVE-2023-34545CRITICAL A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL. | Aug 9, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-6302HIGH A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manage | Nov 27, 2023 | 7.2 | 21 | NO | NO |
CVE-2020-36136HIGH SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php. | Aug 11, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-41436MEDIUM Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Conten | Sep 16, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-6303MEDIUM A vulnerability was found in CSZCMS 1.3.0. It has been classified as problematic. This affects an unknown part of the file /admin/settings/ of the component Site Settings Page. The | Nov 27, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cskaza.
Media articles that mention a CVE ID that affects a product developed by Cskaza — matched by CVE ID, not by vendor name.