Easysoft
Products
4- 6 CVEs
- 1 CVE
- 0 CVEs
- 0 CVEs
Recent CVEs
6| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24216 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php. | ||
| CVE-2022-47745 | Hig | 0.58 | 8.8 | 0.15 | Jan 19, 2023 | ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice. | ||
| CVE-2025-5114 | Med | 0.41 | 6.3 | 0.00 | May 23, 2025 | A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committer. The manipulation of the… | ||
| CVE-2020-21268 | Med | 0.40 | 6.1 | 0.01 | Jun 20, 2023 | Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter. | ||
| CVE-2023-46475 | Med | 0.35 | 5.4 | 0.00 | Nov 2, 2023 | A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code. | ||
| CVE-2019-14731 | Med | 0.35 | 5.4 | 0.01 | Aug 7, 2019 | An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box. |
- risk 0.64cvss 9.8epss 0.01
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
- risk 0.58cvss 8.8epss 0.15
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
- risk 0.41cvss 6.3epss 0.00
A vulnerability has been found in easysoft zentaopms 21.5_20250307 and classified as critical. This vulnerability affects the function Edit of the file /index.php?m=editor&f=edit&filePath=cGhhcjovLy9ldGMvcGFzc3dk&action=edit of the component Committer. The manipulation of the…
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
- risk 0.35cvss 5.4epss 0.00
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.