Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cszcms

First CVE: Feb 7, 2019Active for: 7 yearsTotal CVEs: 30
41.6
VTI Score
High

Cszcms develops a content management system product that, despite a narrow portfolio, sits prominently in the vulnerability landscape and skews strongly toward critical-severity outcomes across its disclosed flaws. The vendor's exposure centers on its flagship CMS offering and recurs through application-layer weakness classes endemic to web-facing content platforms: cross-site scripting, SQL injection, unsafe file uploads, cross-site request forgery, and command injection. These are input-handling and access-control issues characteristic of middleware that accepts and processes untrusted user input at scale, and their prevalence at critical severity reflects the direct pathway such flaws offer to database breach, code execution, and account compromise in web applications. Defenders should treat Cszcms vulnerability disclosures as high-priority for any deployed instances and prioritize patching of the CMS tier; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
2.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cszcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2019
7 years ago
Most Recent CVE
Dec 23, 2025
212 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-13086CRITICAL
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Jun 30, 20199.847NONO
CVE-2021-43701MEDIUM
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.
Mar 29, 20226.534NOYES
CVE-2022-27165CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
Apr 12, 20229.831NONO
CVE-2022-27162CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
Apr 12, 20229.831NONO
CVE-2022-27164CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
Apr 12, 20229.830NONO
CVE-2022-27163CRITICAL
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
Apr 12, 20229.830NONO
CVE-2022-27161CRITICAL
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
Apr 12, 20229.830NONO
CVE-2020-21250CRITICAL
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
Oct 27, 20219.830NONO
CVE-2019-15524CRITICAL
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a ph
Aug 26, 20199.829NONO
CVE-2024-58307HIGH
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers c
Dec 11, 20258.828NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
53%
13%
33%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (56.7%)
Unknown0 (0.0%)
Required13 (43.3%)
Privileges Required
Low13 (43.3%)
High0 (0.0%)
None17 (56.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cszcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cszcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cszcms's Products

View all 2 CNAs →

Top CWEs