CVE-2018-13116: Zzcms

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.

Affected products

  • Zzcms Zzcms: version 8.3. only

Published 2018-07-03. Last modified 2026-06-17.