Zucchetti

    Dashboard / Vendors

    Products: 11
    Vulnerabilities: 25
    Known Exploited: 0
    1
    Critical Level Threats
    11
    High Level Threats
    12
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-30695

    Zucchetti Axess Web Interface XSS via dirBrowse Parameter

    Last Modified: Mar 24, 2026
    Published: Mar 18, 2026

    CVE-2021-47722

    Zucchetti Axess CLOKI Access Control 1.64 Cross-Site Request Forgery

    Last Modified: Apr 15, 2026
    Published: Dec 23, 2025

    CVE-2025-61431

    A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance Infinity and Infinity Zucchetti v4.1 and earlier allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into the pHtmlSource parameter. A vendor fix was released on 2025-06-18.

    Last Modified: Feb 04, 2026
    Published: Nov 04, 2025

    CVE-2025-52180

    Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint.

    Last Modified: Dec 22, 2025
    Published: Oct 30, 2025

    CVE-2025-52179

    Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahrw/jsp/gsfr_feditorHTML.jsp endpoint.

    Last Modified: Apr 15, 2026
    Published: Oct 30, 2025
    Items Per Page