Dzzoffice is a web-based office and collaboration platform that has accumulated security exposure across a concentrated product line, with vulnerabilities skewing toward serious outcomes and frequently acquiring public exploit code. The recurring weakness classes—cross-site scripting, SQL injection, cross-site request forgery, code injection, and authorization flaws—reflect the application-layer input-handling and access-control demands inherent to browser-facing productivity software. Defenders tracking this vendor should prioritize patching for web-tier deployment contexts; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dzzoffice over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3318MEDIUM attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. | Jan 27, 2021 | 6.1 | 30 | NO | YES |
CVE-2025-63695CRITICAL DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php. | Nov 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-63694CRITICAL DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. | Nov 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-43340HIGH A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users. | Oct 27, 2022 | 8.8 | 29 | NO | NO |
CVE-2021-30203MEDIUM A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML. | Jun 27, 2023 | 6.1 | 28 | NO | YES |
CVE-2024-41376HIGH dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php. | Aug 5, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-43673MEDIUM dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(json_encode | Dec 3, 2021 | 6.1 | 22 | NO | NO |
CVE-2020-19703MEDIUM A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Aug 26, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-63693MEDIUM The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTM | Nov 18, 2025 | 5.4 | 20 | NO | NO |
CVE-2021-40292MEDIUM A Stored Cross Site Sripting (XSS) vulnerability exists in DzzOffice 2.02.1 via the settingnew parameter. | Oct 12, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dzzoffice.
Media articles that mention a CVE ID that affects a product developed by Dzzoffice — matched by CVE ID, not by vendor name.