Zkea maintains a focused content-management system product, ZkeaCMS, that despite a narrow portfolio carries a disproportionate severity profile. Vulnerabilities affecting the vendor skew toward critical outcomes and cluster around web-application weaknesses including server-side request forgery, unrestricted file upload, path traversal, and cross-site scripting—classes that arise from insufficient input validation and access controls in request handling. Defenders should treat updates for this product as high-priority; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zkea over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-52239CRITICAL An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file. | Aug 4, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10764HIGH A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the compone | Sep 21, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-10471HIGH A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipulation of the argument url resu | Sep 15, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-10765HIGH A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEO | Sep 21, 2025 | 7.2 | 23 | NO | NO |
CVE-2020-20670HIGH An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file. | Sep 13, 2021 | 8.8 | 22 | NO | NO |
CVE-2022-29362MEDIUM A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje | May 25, 2022 | 5.4 | 20 | NO | NO |
CVE-2025-10766MEDIUM A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument | Sep 21, 2025 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zkea.
Media articles that mention a CVE ID that affects a product developed by Zkea — matched by CVE ID, not by vendor name.