CVE-2020-29312
- EPSS 1.87%
- Published 04.04.2023 15:15:08
- Last modified 18.02.2025 17:15:11
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and incorrect. The framework does not have a version that ...
CVE-2021-3007
- EPSS 66.84%
- Published 04.01.2021 03:15:13
- Last modified 21.11.2024 06:20:44
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the __destruct method of the Zend\Http\Response\Stream class i...
CVE-2014-8089
- EPSS 1.12%
- Published 17.02.2020 22:15:11
- Last modified 21.11.2024 02:18:31
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.
CVE-2015-3154
- EPSS 0.27%
- Published 27.01.2020 16:15:11
- Last modified 21.11.2024 02:28:47
CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences i...
CVE-2012-4451
- EPSS 1.78%
- Published 03.01.2020 17:15:11
- Last modified 21.11.2024 01:42:55
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Dec...
CVE-2014-4913
- EPSS 0.57%
- Published 15.12.2019 22:15:11
- Last modified 21.11.2024 02:11:06
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
CVE-2011-1939
- EPSS 8.54%
- Published 26.11.2019 22:15:14
- Last modified 21.11.2024 01:27:21
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
CVE-2014-4914
- EPSS 3.44%
- Published 29.12.2017 14:29:00
- Last modified 20.04.2025 01:37:25
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2015-7503
- EPSS 0.25%
- Published 10.10.2017 16:29:00
- Last modified 20.04.2025 01:37:25
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.
CVE-2015-1555
- EPSS 0.29%
- Published 07.08.2017 17:29:00
- Last modified 20.04.2025 01:37:25
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.