CVE-2018-1000653: Zzcms

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

zzcms version 8.3 and earlier contains a SQL Injection vulnerability in zt/top.php line 5 that can result in could be attacked by sql injection in zzcms in nginx. This attack appear to be exploitable via running zzcms in nginx.

Affected products

  • Zzcms Zzcms: up to and including 8.3

Published 2018-08-20. Last modified 2026-06-17.