Juzaweb is a content management system whose vulnerability profile centers on its core CMS product and recurs through authorization and access-control weaknesses alongside cross-site scripting issues typical of web application platforms. The vendor's durable exposure signal reflects common CMS-layer input-handling and privilege-management challenges rather than infrastructure-level flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Juzaweb over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-6736HIGH A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the compone | Jun 27, 2025 | 8.8 | 22 | NO | NO |
CVE-2025-6735HIGH A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipula | Jun 27, 2025 | 8.8 | 22 | NO | NO |
CVE-2023-46468HIGH An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function. | Oct 28, 2023 | 7.8 | 22 | NO | NO |
CVE-2025-5428MEDIUM A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of the component Error Logs Page. Th | Jun 2, 2025 | 6.3 | 19 | NO | NO |
CVE-2025-5427MEDIUM A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin-cp/permalinks of the co | Jun 2, 2025 | 6.3 | 19 | NO | NO |
CVE-2025-5429MEDIUM A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/install of the component Plugins P | Jun 2, 2025 | 6.3 | 18 | NO | NO |
CVE-2025-5426MEDIUM A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-cp/menus of th | Jun 2, 2025 | 6.3 | 18 | NO | NO |
CVE-2025-5425MEDIUM A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme/editor/default of the componen | Jun 2, 2025 | 6.3 | 18 | NO | NO |
CVE-2025-5424MEDIUM A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the file /admin-cp/media of the component Media Page. | Jun 2, 2025 | 6.3 | 18 | NO | NO |
CVE-2025-5423MEDIUM A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/setting/system/general of the co | Jun 2, 2025 | 6.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Juzaweb.
Media articles that mention a CVE ID that affects a product developed by Juzaweb — matched by CVE ID, not by vendor name.