VYPR

Zentaopms

by Easysoft

CVEs (6)

  • CVE-2024-24216CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.

  • CVE-2022-47745HigJan 19, 2023
    risk 0.58cvss 8.8epss 0.15

    ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.

  • CVE-2025-5114MedMay 23, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committer. The manipulation of the…

  • CVE-2020-21268MedJun 20, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.

  • CVE-2023-46475MedNov 2, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.

  • CVE-2019-14731MedAug 7, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.