Cszcms develops a content management system product that, despite a narrow portfolio, sits prominently in the vulnerability landscape and skews strongly toward critical-severity outcomes across its disclosed flaws. The vendor's exposure centers on its flagship CMS offering and recurs through application-layer weakness classes endemic to web-facing content platforms: cross-site scripting, SQL injection, unsafe file uploads, cross-site request forgery, and command injection. These are input-handling and access-control issues characteristic of middleware that accepts and processes untrusted user input at scale, and their prevalence at critical severity reflects the direct pathway such flaws offer to database breach, code execution, and account compromise in web applications. Defenders should treat Cszcms vulnerability disclosures as high-priority for any deployed instances and prioritize patching of the CMS tier; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cszcms over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13086CRITICAL core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter. | Jun 30, 2019 | 9.8 | 47 | NO | NO |
CVE-2021-43701MEDIUM CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters. | Mar 29, 2022 | 6.5 | 34 | NO | YES |
CVE-2022-27165CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27162CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27164CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27163CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27161CRITICAL Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-21250CRITICAL CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | Oct 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-15524CRITICAL CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a ph | Aug 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2024-58307HIGH CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers c | Dec 11, 2025 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cszcms.
Media articles that mention a CVE ID that affects a product developed by Cszcms — matched by CVE ID, not by vendor name.