Vulnerabilities (CVE)

Filtered by vendor Cszcms Subscribe
Filtered by product Csz Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-39599 1 Cszcms 1 Csz Cms 2023-08-28 N/A 5.4 MEDIUM
Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.
CVE-2023-38911 1 Cszcms 1 Csz Cms 2023-08-22 N/A 5.4 MEDIUM
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.
CVE-2023-38910 1 Cszcms 1 Csz Cms 2023-08-22 N/A 6.1 MEDIUM
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
CVE-2021-26776 1 Cszcms 1 Csz Cms 2021-03-17 3.5 LOW 5.4 MEDIUM
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
CVE-2021-3224 1 Cszcms 1 Csz Cms 2021-03-12 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.