CVE detail
CVE-2025-14836
A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes cleartext storage in a file or on disk. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://vuldb.com/?submit.711654vuldb.com
No excerpt available.
Exploitvuldb.comDec 17, 2025, 11:15 PM - https://vuldb.com/?id.336986vuldb.com
No excerpt available.
Exploitvuldb.comDec 17, 2025, 11:15 PM - https://vuldb.com/?ctiid.336986vuldb.com
No excerpt available.
Exploitvuldb.comDec 17, 2025, 11:15 PM - https://note-hxlab.wetolink.com/share/bu2KYevoyBm6note-hxlab.wetolink.com
No excerpt available.
Exploitnote-hxlab.wetolink.comDec 17, 2025, 11:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-8804CVSS 6.7 · Medium
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing…
- CVE-2026-6796CVSS 5.3 · Medium
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminCo…
- CVE-2026-6598CVSS 2.1 · Low
A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/b…
- CVE-2026-5531CVSS 5.5 · Medium
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET…
- CVE-2025-6748CVSS 0.9 · Low
A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/…
- CVE-2025-5154CVSS 4.6 · Medium
A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databa…