Zkup is a niche application with a focused vulnerability footprint centered on authentication and code-injection weaknesses that reflect input-handling and access-control risks in its core product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zkup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7124HIGH zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a d | Aug 31, 2009 | 7.5 | 32 | NO | YES |
CVE-2008-7123MEDIUM Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 through 2.3 allows remote attackers to inject arbitrary PHP code into fichiers/config.php vi | Aug 31, 2009 | 6.8 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zkup.
Media articles that mention a CVE ID that affects a product developed by Zkup — matched by CVE ID, not by vendor name.