CVE-2025-5114
- EPSS 0.11%
- Veröffentlicht 23.05.2025 14:31:04
- Zuletzt bearbeitet 05.12.2025 00:16:57
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committe...
CVE-2024-24216
- EPSS 4.89%
- Veröffentlicht 08.02.2024 06:15:51
- Zuletzt bearbeitet 08.05.2025 19:15:59
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
CVE-2024-24202
- EPSS 0.12%
- Veröffentlicht 08.02.2024 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:59:01
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
CVE-2023-49394
- EPSS 0.2%
- Veröffentlicht 10.01.2024 09:15:44
- Zuletzt bearbeitet 03.06.2025 15:15:43
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
CVE-2023-6439
- EPSS 0.15%
- Veröffentlicht 30.11.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:51
A vulnerability classified as problematic was found in ZenTao PMS 18.8. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to...
CVE-2023-46475
- EPSS 0.08%
- Veröffentlicht 02.11.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:33
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
CVE-2023-44826
- EPSS 0.19%
- Veröffentlicht 10.10.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:26:03
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
CVE-2023-44827
- EPSS 0.25%
- Veröffentlicht 10.10.2023 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:26:04
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
CVE-2020-21268
- EPSS 0.17%
- Veröffentlicht 20.06.2023 15:15:11
- Zuletzt bearbeitet 09.12.2024 22:15:20
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
CVE-2020-22533
- EPSS 0.23%
- Veröffentlicht 04.04.2023 15:15:08
- Zuletzt bearbeitet 13.02.2025 17:15:26
Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter