Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zzcms

First CVE: Feb 24, 2018Active for: 8 yearsTotal CVEs: 107
50.6
VTI Score
TOP TARGET

Zzcms is a content-management system that, despite a narrow product footprint spanning Zzcms and Zzmcms variants, has accumulated a moderate volume of disclosures and occupies a notable position in the vulnerability landscape, likely due to wide deployment in web-hosting and site-building contexts. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting fundamental input-handling weaknesses across the application layer. The exposure recurs persistently through SQL injection, path traversal, cross-site scripting, code injection, and broader injection flaws—a cohesive family of input-neutralization and output-encoding failures that are endemic to web applications with inconsistent sanitization practices. Defenders should treat Zzcms deployments as high-risk, prioritize patching for this vendor's advisories, and consider compensating controls for instances where timely updates are not feasible. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
107
Total CVEs
More Total CVEs than 99% of tracked vendors
6.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zzcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2018
8 years ago
Most Recent CVE
Dec 18, 2025
218 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (107 CVEs).

107 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-12351CRITICAL
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.
Jun 2, 20229.831NONO
CVE-2019-12350CRITICAL
An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.
Jun 2, 20229.831NONO
CVE-2019-12349CRITICAL
An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
Jun 2, 20229.831NONO
CVE-2019-1010148CRITICAL
zzcms version 8.3 and earlier is affected by: SQL Injection. The impact is: zzcms File Delete to Code Execution.
Jul 23, 20199.831NONO
CVE-2018-18789CRITICAL
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
Oct 29, 20189.831NONO
CVE-2018-18787CRITICAL
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
Oct 29, 20189.831NONO
CVE-2018-18786CRITICAL
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
Oct 29, 20189.831NONO
CVE-2018-18785CRITICAL
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
Oct 29, 20189.831NONO
CVE-2018-8967CRITICAL
An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request.
Mar 24, 20189.831NONO
CVE-2023-50104CRITICAL
ZZCMS 2023 has a file upload vulnerability in 3/E_bak5.1/upload/index.php, allowing attackers to exploit this loophole to gain server privileges and execute arbitrary code.
Dec 29, 20239.830NONO
View all 107 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products107 CVEs
22%
45%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network107 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low107 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None89 (83.2%)
Unknown0 (0.0%)
Required18 (16.8%)
Privileges Required
Low19 (17.8%)
High20 (18.7%)
None68 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (107 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
1.9% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zzcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zzcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zzcms's Products

View all 3 CNAs →

Top CWEs