← Vulnerability feed

Vulnerability record · CVE-2020-18717 · published 5 February 2021

CVE-2020-18717: Zzzcms zzzphp sql injection vulnerability

Zzzcms · Zzzphp

SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

9.8 CVSS 3.1 Critical EPSS 3.6% · top 11.0% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
3.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.seebug.org/vuldb/ssvid-98031 ExploitThird Party Advisory
https://www.seebug.org/vuldb/ssvid-98031 ExploitThird Party Advisory

Track CVE-2020-18717 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-9082ThinkPHP invokefunction parameter allows remote command executionThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafte…KEVEPSS 97%analysed9.8CVE-2022-23881ZZZCMS zzzphp danger_key() remote command executionZZZCMS zzzphp v2.1.0 contains a remote command execution flaw reached through the danger_key() function in zzz_template.php. The CVSS 3.1 base score …EPSS 57%analysed9.8CVE-2021-32605Zzzcms zzzphp os command injection vulnerabilityzzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, …EPSS 3.8%9.8CVE-2020-24877Zzzcms zzzphp sql injection vulnerabilityA SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.EPSS 2.1%9.8CVE-2020-20298Zzzcms zzzphp code injection vulnerabilityEval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to ex…EPSS 2.7%9.8CVE-2019-17408Zzzcms zzzphp code injection vulnerabilityparserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be…EPSS 3.7%9.8CVE-2019-16722Zzzcms zzzphp vulnerabilityZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an str_ireplace operation.EPSS 3.1%9.8CVE-2019-10647Zzzcms zzzphp unrestricted file upload vulnerabilityZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/controller.php?action=catchimage…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2020-18717), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.