Zzcms is a content-management system that, despite a narrow product footprint spanning Zzcms and Zzmcms variants, has accumulated a moderate volume of disclosures and occupies a notable position in the vulnerability landscape, likely due to wide deployment in web-hosting and site-building contexts. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting fundamental input-handling weaknesses across the application layer. The exposure recurs persistently through SQL injection, path traversal, cross-site scripting, code injection, and broader injection flaws—a cohesive family of input-neutralization and output-encoding failures that are endemic to web applications with inconsistent sanitization practices. Defenders should treat Zzcms deployments as high-risk, prioritize patching for this vendor's advisories, and consider compensating controls for instances where timely updates are not feasible. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zzcms over time
Signals from CVEs in this vendor scope (107 CVEs).
107 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12351CRITICAL An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-12350CRITICAL An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-12349CRITICAL An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-1010148CRITICAL zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution. | Jul 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-18789CRITICAL An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-18787CRITICAL An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-18786CRITICAL An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-18785CRITICAL An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-8967CRITICAL An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. | Mar 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2023-50104CRITICAL ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code. | Dec 29, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (107 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zzcms.
Media articles that mention a CVE ID that affects a product developed by Zzcms — matched by CVE ID, not by vendor name.