ZeroHour

Vulnerabilities

632 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-29934
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the cont

A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.

NVD description · AI analysis pending
6.1<1% PoC
  • lightcms project lightcms
CVE-2020-37076
+2 in the same advisory: …37073 …37072
Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries.

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • victor cms project victor cms
CVE-2020-36942
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature.

Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.

NVD description · AI analysis pending
8.7<1% PoC
  • victor cms project victor cms
CVE-2022-50895
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries.

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

NVD description · AI analysis pending
8.8<1% PoC ×3
  • aerocms project aerocms
CVE-2025-14731
A weakness has been identified in CTCMS Content Management System up to 2.1.2.

A weakness has been identified in CTCMS Content Management System up to 2.1.2. This affects an unknown function in the library /ctcms/apps/libraries/CT_Parser.php of the component Frontend/Template Management Module. This manipulation causes improper neutralization of special elements used in a template engine. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • ctcms project ctcms
CVE-2025-14730
+1 in the same advisory: …14729
A security flaw has been discovered in CTCMS Content Management System up to 2.1.2.

A security flaw has been discovered in CTCMS Content Management System up to 2.1.2. The impacted element is an unknown function in the library /ctcms/libs/Ct_Config.php of the component Backend System Configuration Module. The manipulation of the argument Cj_Add/Cj_Edit results in code injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

NVD description · AI analysis pending
2.0<1% PoC
  • ctcms project ctcms
CVE-2025-13786
+2 in the same advisory: …13782 …13783
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665.

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.5
group max
<1% PoC ×2
  • wtcms project wtcms
CVE-2025-11138
A vulnerability was found in mirweiye wenkucms up to 3.4.

A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used.

NVD description · AI analysis pending
2.14% PoC
  • wenkucms project wenkucms
CVE-2025-55835
File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.

NVD description · AI analysis pending
9.8<1% PoC
  • sueamcms project sueamcms
CVE-2025-56407
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical.

A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
8.8<1%
  • utcms project utcms
CVE-2025-9401
+1 in the same advisory: …9402
A vulnerability has been found in HuangDou UTCMS 9.

A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument code leads to incorrect comparison. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.9
group max
<1%
  • utcms project utcms
CVE-2025-7099
+4 in the same advisory: …7101 …7103 …7102 …7100
A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical.

A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.php of the component Installation Handler. The manipulation of the argument db_host leads to deserialization. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.9
group max
<1%
  • boyuncms project boyuncms
CVE-2025-5033
A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2.

A vulnerability classified as problematic was found in XiaoBingby TeaCMS 2.0.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/me/teacms/controller/admin/UserManageController/addUser. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • teacms project teacms
CVE-2025-44831
EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.

NVD description · AI analysis pending
9.8<1% PoC
  • engineercms project engineercms
CVE-2025-44830
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

NVD description · AI analysis pending
9.8<1% PoC
  • engineercms project engineercms
CVE-2025-4545
A vulnerability was found in CTCMS Content Management System 2.1.2.

A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php of the component File Handler. The manipulation of the argument File leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • ctcms project ctcms
CVE-2025-29058
An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.

An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component.

NVD description · AI analysis pending
9.8<1%
  • qimou cms project qimou cms
CVE-2025-29150
BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

NVD description · AI analysis pending
4.3<1% PoC
  • bluecms project bluecms
CVE-2025-3386
+1 in the same advisory: …3385
A vulnerability was found in LinZhaoguan pb-cms 2.0.

A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • pb-cms project pb-cms
CVE-2025-3177
A vulnerability was found in FastCMS 0.1.5.

A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.3<1% PoC
  • fastcms project fastcms
CVE-2025-2043
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical.

A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1%
  • pb-cms project pb-cms
CVE-2025-1890
A vulnerability has been found in shishuocms 1.1 and classified as critical.

A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • shishuocms project shishuocms
CVE-2025-1745
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic.

A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • pb-cms project pb-cms
CVE-2025-25759
+1 in the same advisory: …25760
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET reque

An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request.

NVD description · AI analysis pending
7.5<1%
  • sucms project sucms
CVE-2025-1557
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3.

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • ofcms project ofcms
CVE-2025-0482
+4 in the same advisory: …0490 …0489 …0488 …0483
A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0.

A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9
group max
<1% PoC ×2
  • native-php-cms project native-php-cms
CVE-2024-51229
Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

NVD description · AI analysis pending
8.8<1% PoC
  • pb-cms project pb-cms
CVE-2024-13194
A vulnerability was found in Sucms 1.0 and classified as critical.

A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • sucms project sucms
CVE-2024-10479
+2 in the same advisory: …10478 …10477
A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1.

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1% PoC
  • pb-cms project pb-cms
CVE-2024-48237
+2 in the same advisory: …48239 …48238
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • wtcms project wtcms