Csz Cms

Vendor:

First CVE: Feb 7, 2019 · Active for 7 years

30
Total CVEs
More Total CVEs than 96% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Csz Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2019
7 years ago
Most Recent CVE
Dec 23, 2025
214 days ago

CVE Severity & Scoring

Csz Cms30 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (56.7%)
Unknown0 (0.0%)
Required13 (43.3%)
Privileges Required
Low13 (43.3%)
High0 (0.0%)
None17 (56.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter.
Jun 30, 20199.847NONO
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters.
Mar 29, 20226.534NOYES
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
Apr 12, 20229.831NONO
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser
Apr 12, 20229.831NONO
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers
Apr 12, 20229.830NONO
CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser
Apr 12, 20229.830NONO
Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers
Apr 12, 20229.830NONO
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
Oct 27, 20219.830NONO
CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a ph
Aug 26, 20199.829NONO
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers c
Dec 11, 20258.828NONO

Exploit Exposure

Signals from CVEs in this product scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (30 CVEs).

Media Mentions

Signals from CVEs in this product scope (30 CVEs).

Top CNAs Publishing CVEs For Csz Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.3.0116.70.7%00
1.2.966.21.1%01
1.2.725.40.3%00
1.2.419.81.1%00
1.2.319.83.1%00
1.2.269.61.1%00
1.1.818.80.7%00