CVE-2023-46906: Juzaweb CMS

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone field was not correctly validated.

Affected products

  • Juzaweb CMS: up to and including 3.4

Published 2024-01-09. Last modified 2026-06-17.