Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zzzcms

First CVE: Dec 13, 2018Active for: 8 yearsTotal CVEs: 20
83.6
VTI Score
TOP TARGET

Zzzcms maintains a narrow portfolio centered on PHP-based content-management and web-application products that, despite modest prevalence, occupy a more prominent position in the vulnerability landscape than their apparent market footprint would suggest. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the accessible nature of web-application flaws and the appeal of these products as targets for mass exploitation. The exposure recurs consistently across the ZzzPHP and Zzzcms products through a durable set of input-handling and code-generation weakness classes—unrestricted file upload, code injection, SQL injection, CSRF, and improper input validation—that are characteristic of PHP web frameworks and indicate systemic validation and access-control gaps rather than isolated incidents. Defenders should treat updates to this vendor's products as high-priority and inventory instances with particular attention to upload and administrative functions; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
5.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zzzcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2018
7 years ago
Most Recent CVE
Oct 25, 2023
1,003 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-9082HIGH
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_
Feb 24, 20198.899YESYES
CVE-2022-23881CRITICAL
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
Mar 23, 20229.873NOYES
CVE-2019-9041HIGH
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demon
Feb 23, 20197.252NOYES
CVE-2019-10647CRITICAL
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of
Mar 30, 20199.845NOYES
CVE-2020-18717CRITICAL
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
Feb 5, 20219.831NONO
CVE-2019-17408CRITICAL
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations suc
Oct 14, 20199.831NONO
CVE-2019-16722CRITICAL
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
Sep 23, 20199.831NONO
CVE-2021-32605CRITICAL
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS comman
May 11, 20219.830NONO
CVE-2020-24877CRITICAL
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
Mar 15, 20219.830NONO
CVE-2020-20298CRITICAL
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
Dec 18, 20209.829NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
15%
40%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (65.0%)
Unknown0 (0.0%)
Required7 (35.0%)
Privileges Required
Low3 (15.0%)
High1 (5.0%)
None16 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
1 CVE
5.0% of CVEs· 99th percentile
Metasploit
1 CVE
5.0% of CVEs· 98th percentile
Nuclei
4 CVEs
20.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zzzcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zzzcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zzzcms's Products

View all 2 CNAs →

Top CWEs