Zzzcms maintains a narrow portfolio centered on PHP-based content-management and web-application products that, despite modest prevalence, occupy a more prominent position in the vulnerability landscape than their apparent market footprint would suggest. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, reflecting the accessible nature of web-application flaws and the appeal of these products as targets for mass exploitation. The exposure recurs consistently across the ZzzPHP and Zzzcms products through a durable set of input-handling and code-generation weakness classes—unrestricted file upload, code injection, SQL injection, CSRF, and improper input validation—that are characteristic of PHP web frameworks and indicate systemic validation and access-control gaps rather than isolated incidents. Defenders should treat updates to this vendor's products as high-priority and inventory instances with particular attention to upload and administrative functions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zzzcms over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9082HIGH ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_ | Feb 24, 2019 | 8.8 | 99 | YES | YES |
CVE-2022-23881CRITICAL ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | Mar 23, 2022 | 9.8 | 73 | NO | YES |
CVE-2019-9041HIGH An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demon | Feb 23, 2019 | 7.2 | 52 | NO | YES |
CVE-2019-10647CRITICAL ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of | Mar 30, 2019 | 9.8 | 45 | NO | YES |
CVE-2020-18717CRITICAL SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | Feb 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-17408CRITICAL parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations suc | Oct 14, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16722CRITICAL ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation. | Sep 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-32605CRITICAL zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS comman | May 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-24877CRITICAL A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | Mar 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-20298CRITICAL Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. | Dec 18, 2020 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zzzcms.
Media articles that mention a CVE ID that affects a product developed by Zzzcms — matched by CVE ID, not by vendor name.