Zzzphp

Vendor:

First CVE: Dec 13, 2018 · Active for 7 years

14
Total CVEs
More Total CVEs than 91% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 82% of tracked products
7.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Zzzphp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 13, 2018
7 years ago
Most Recent CVE
Oct 18, 2023
1,010 days ago

CVE Severity & Scoring

Zzzphp14 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (78.6%)
Unknown0 (0.0%)
Required3 (21.4%)
Privileges Required
Low0 (0.0%)
High1 (7.1%)
None13 (92.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_
Feb 24, 20198.899YESYES
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
Mar 23, 20229.873NOYES
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the parserIfLabel() function's filtering is not strict, resulting in PHP code execution, as demon
Feb 23, 20197.252NOYES
ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage source[] parameter because of
Mar 30, 20199.845NOYES
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
Feb 5, 20219.831NONO
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations suc
Oct 14, 20199.831NONO
ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.
Sep 23, 20199.831NONO
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS comman
May 11, 20219.830NONO
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
Mar 15, 20219.830NONO
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
Dec 18, 20209.829NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
1 CVE
7.1% of CVEs· 97th percentile
Metasploit
1 CVE
7.1% of CVEs· 97th percentile
Nuclei
4 CVEs
28.6% of CVEs· 98th percentile
ExploitDB
2 CVEs
14.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Zzzphp

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2.016.10.3%00
2.1.019.856.5%01
1.8.019.82.1%00
1.7.319.83.7%00
1.7.239.02.4%00
1.7.119.83.6%00
1.6.319.86.6%01
1.6.138.343.2%12
1.5.817.51.4%00