Zkea Zkeacms vulnerabilities
7 known vulnerabilities affecting zkea/zkeacms.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-10764P2HIGHCVSS 8.8≤ 4.32025-09-21
CVE-2025-10764 [HIGH] CWE-918 CVE-2025-10764: A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the
A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.EventAction/Controllers/PendingTaskController.cs of the component Event Action System. Such manipulation of the argument Data leads to server-side request forgery. The attack may be performed from remote. The exploit is publicly availabl
nvd
CVE-2025-10471P3HIGHCVSS 8.8v4.32025-09-15
CVE-2025-10471 [HIGH] CWE-918 CVE-2025-10471: A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/
A vulnerability was detected in ZKEACMS 4.3. Impacted is the function Proxy of the file src/ZKEACMS/Controllers/MediaController.cs. Performing manipulation of the argument url results in server-side request forgery. It is possible to initiate the attack remotely. The exploit is now public and may be used.
nvd
CVE-2025-52239P3CRITICALCVSS 9.8v4.12025-08-04
CVE-2025-52239 [CRITICAL] CWE-434 CVE-2025-52239: An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code vi
An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
nvd
CVE-2025-10765P3HIGHCVSS 7.2≤ 4.32025-09-21
CVE-2025-10765 [HIGH] CWE-918 CVE-2025-10765: A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the fu
A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Suggestions in the library cms-v4.3\wwwroot\Plugins\ZKEACMS.SEOSuggestions\ZKEACMS.SEOSuggestions.dll of the component SEOSuggestions. Performing manipulation results in server-side request forgery. It is possible to initiate the attack
nvd
CVE-2020-20670P3HIGHCVSS 8.8v3.2.02021-09-13
CVE-2020-20670 [HIGH] CWE-434 CVE-2020-20670: An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to
An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.
nvd
CVE-2025-10766P4MEDIUMCVSS 4.3≤ 4.32025-09-21
CVE-2025-10766 [MEDIUM] CWE-22 CVE-2025-10766: A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Downlo
A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file EventViewerController.cs. Executing manipulation of the argument ID can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contac
nvd
CVE-2022-29362P4MEDIUMCVSS 5.4v3.5.22022-05-25
CVE-2022-29362 [MEDIUM] CWE-79 CVE-2022-29362: A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allo
A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ParentID parameter.
nvd