Zbzcms is a niche content-management system with a focused product portfolio that exhibits a strong tendency toward critical-severity vulnerabilities across its codebase. The recurring exposure centers on foundational web-application weaknesses including SQL injection, unrestricted file uploads, and cross-site scripting, which are characteristic of input-validation and file-handling gaps in less-mature CMS platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zbzcms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27126CRITICAL zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php. | Apr 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-27131CRITICAL An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | Apr 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27129CRITICAL An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | Apr 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27128CRITICAL An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts. | Apr 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27133CRITICAL zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php. | Apr 10, 2022 | 9.1 | 28 | NO | NO |
CVE-2022-27127MEDIUM zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php/ajax.php. | Apr 10, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-27125MEDIUM zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /php/ajax.php. | Apr 10, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zbzcms.
Media articles that mention a CVE ID that affects a product developed by Zbzcms — matched by CVE ID, not by vendor name.