Products: 21
    Vulnerabilities: 49
    Known Exploited: 0
    14
    Critical Level Threats
    8
    High Level Threats
    26
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-34508

    ZendTo < 6.15-8 Path Traversal

    Last Modified: Apr 15, 2026
    Published: Jun 17, 2025

    CVE-2021-47667

    An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

    Last Modified: Apr 15, 2026
    Published: Apr 05, 2025

    CVE-2025-32352

    A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes that can be interpreted as numbers. A solution requires moving from MD5 to bcrypt.

    Last Modified: Apr 15, 2026
    Published: Apr 05, 2025

    CVE-2024-9129

    Format String Injection in Zend Server

    Last Modified: Apr 15, 2026
    Published: Oct 22, 2024

    CVE-2020-29312

    An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that surpasses 2.x.x and was deprecated in early 2020.

    Last Modified: Feb 18, 2025
    Published: Apr 04, 2023
    Items Per Page