Skip to main content
CRITICAL

CVE-2021-37144

CVSS v3

9.1

CRITICAL

EPSS Score

1.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Technical details

Published
2021-07-30

Frequently asked questions

What is CVE-2021-37144?

CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.

Is CVE-2021-37144 actively exploited?

Active exploitation of CVE-2021-37144 has not been confirmed. Its EPSS score was 1.3% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-37144?

CVE-2021-37144 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2021-37144 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key