Zzzphp
Vendor:
First CVE: Dec 13, 2018 · Active for 7 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 82% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Zzzphp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2018
7 years ago
Most Recent CVE
Oct 18, 2023
1,010 days ago
CVE Severity & Scoring
Zzzphp14 CVEs
36%
57%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None13 (92.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9082HIGH ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_ | Feb 24, 2019 | 8.8 | 99 | YES | YES |
CVE-2022-23881CRITICAL ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php. | Mar 23, 2022 | 9.8 | 73 | NO | YES |
CVE-2019-9041HIGH An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demon | Feb 23, 2019 | 7.2 | 52 | NO | YES |
CVE-2019-10647CRITICAL ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of | Mar 30, 2019 | 9.8 | 45 | NO | YES |
CVE-2020-18717CRITICAL SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | Feb 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-17408CRITICAL parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations suc | Oct 14, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16722CRITICAL ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation. | Sep 23, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-32605CRITICAL zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS comman | May 11, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-24877CRITICAL A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | Mar 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-20298CRITICAL Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. | Dec 18, 2020 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
4 CVEs
28.6% of CVEs· 98th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Zzzphp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.2.0 | 1 | 6.1 | 0.3% | 0 | 0 |
| 2.1.0 | 1 | 9.8 | 56.5% | 0 | 1 |
| 1.8.0 | 1 | 9.8 | 2.1% | 0 | 0 |
| 1.7.3 | 1 | 9.8 | 3.7% | 0 | 0 |
| 1.7.2 | 3 | 9.0 | 2.4% | 0 | 0 |
| 1.7.1 | 1 | 9.8 | 3.6% | 0 | 0 |
| 1.6.3 | 1 | 9.8 | 6.6% | 0 | 1 |
| 1.6.1 | 3 | 8.3 | 43.2% | 1 | 2 |
| 1.5.8 | 1 | 7.5 | 1.4% | 0 | 0 |