CVE-2025-63608: Cszcms Csz CMS
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
A SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field parameter of the form viewing feature, allowing authenticated administrators to execute arbitrary SQL queries.
Affected products
- Cszcms Csz CMS: up to and including 1.3.0
Published 2025-10-30. Last modified 2026-06-17.