Skip to main content

Vendor/product archive

juzaweb / cms CVEs

Beta · best-effort

15 CVEs tagged to juzaweb / cms0 Critical, 0 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2025-6736

Published Jun 27, 2025

A vulnerability classified as critical was found in juzaweb CMS 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/theme/install of the compon…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6735

Published Jun 27, 2025

A vulnerability classified as critical has been found in juzaweb CMS 3.4.2. Affected is an unknown function of the file /admin-cp/imports of the component Import Page. The manipul…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5429

Published Jun 2, 2025

A vulnerability classified as critical was found in juzaweb CMS up to 3.4.2. This vulnerability affects unknown code of the file /admin-cp/plugin/install of the component Plugins…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5428

Published Jun 2, 2025

A vulnerability classified as critical has been found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/log-viewer of the component Error Logs Page. T…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5427

Published Jun 2, 2025

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin-cp/permalinks of the c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5426

Published Jun 2, 2025

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin-cp/menus of t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5425

Published Jun 2, 2025

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as critical. Affected is an unknown function of the file /admin-cp/theme/editor/default of the compone…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5424

Published Jun 2, 2025

A vulnerability was found in juzaweb CMS up to 3.4.2 and classified as critical. This issue affects some unknown processing of the file /admin-cp/media of the component Media Page…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5423

Published Jun 2, 2025

A vulnerability has been found in juzaweb CMS up to 3.4.2 and classified as critical. This vulnerability affects unknown code of the file /admin-cp/setting/system/general of the c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5422

Published Jun 2, 2025

A vulnerability, which was classified as problematic, was found in juzaweb CMS up to 3.4.2. This affects an unknown part of the file /admin-cp/logs/email of the component Email Lo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5421

Published Jun 2, 2025

A vulnerability, which was classified as critical, has been found in juzaweb CMS up to 3.4.2. Affected by this issue is some unknown functionality of the file /admin-cp/plugin/edi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5420

Published Jun 2, 2025

A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/file-manager/uploa…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7551

Published Aug 6, 2024

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the comp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46906

Published Jan 9, 2024

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly vali…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46467

Published Oct 28, 2023

Cross Site Scripting vulnerability in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter of the registr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1