Csz Cms
Vendor:
First CVE: Feb 7, 2019 · Active for 7 years
30
Total CVEs
More Total CVEs than 96% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Csz Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2019
7 years ago
Most Recent CVE
Dec 23, 2025
214 days ago
CVE Severity & Scoring
Csz Cms30 CVEs
53%
13%
33%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network30 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (56.7%)
Unknown0 (0.0%)
Required13 (43.3%)
Privileges Required
Low13 (43.3%)
High0 (0.0%)
None17 (56.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13086CRITICAL core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP User-Agent header and omitting the csrf_csz parameter. | Jun 30, 2019 | 9.8 | 47 | NO | NO |
CVE-2021-43701MEDIUM CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/article_db, via the fieldS[] and orderby parameters. | Mar 29, 2022 | 6.5 | 34 | NO | YES |
CVE-2022-27165CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27162CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27164CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27163CRITICAL CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27161CRITICAL Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers | Apr 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-21250CRITICAL CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | Oct 27, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-15524CRITICAL CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management Module, which leads to remote code execution by visiting a ph | Aug 26, 2019 | 9.8 | 29 | NO | NO |
CVE-2024-58307HIGH CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers c | Dec 11, 2025 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (30 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (30 CVEs).
Media Mentions
Signals from CVEs in this product scope (30 CVEs).
Top CNAs Publishing CVEs For Csz Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.0 | 11 | 6.7 | 0.7% | 0 | 0 |
| 1.2.9 | 6 | 6.2 | 1.1% | 0 | 1 |
| 1.2.7 | 2 | 5.4 | 0.3% | 0 | 0 |
| 1.2.4 | 1 | 9.8 | 1.1% | 0 | 0 |
| 1.2.3 | 1 | 9.8 | 3.1% | 0 | 0 |
| 1.2.2 | 6 | 9.6 | 1.1% | 0 | 0 |
| 1.1.8 | 1 | 8.8 | 0.7% | 0 | 0 |