Zhicms is a content management system with a focused product footprint that exposes application-layer defects centered on unsafe deserialization, code injection, and SQL injection vulnerabilities. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zhicms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2015HIGH A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The | Mar 21, 2024 | 8.8 | 30 | NO | NO |
CVE-2024-2016HIGH A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of | Mar 21, 2024 | 8.8 | 28 | NO | NO |
CVE-2024-0603CRITICAL A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the | Jan 16, 2024 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zhicms.
Media articles that mention a CVE ID that affects a product developed by Zhicms — matched by CVE ID, not by vendor name.