CVE-2022-28522: Zcms Project Zcms

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add.

Affected products

Published 2022-04-26. Last modified 2026-06-17.