Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zend Framework CRITICAL 9.8
CVE-2020-29312

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…

Fix: after 3.1.3
Fix from $2,300 2023-04-04
Zendto MEDIUM 6.1
CVE-2021-27888

ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

Fix: after 6.05-4
Fix from $1,600 2021-03-02
Zendto CRITICAL 9.8
CVE-2020-8986

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to g…

Mitigation only
Fix from $2,300 2020-03-24
Zendto HIGH 8.8
CVE-2020-8985

ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

Mitigation only
Fix from $1,950 2020-03-24
Zendto HIGH 7.5
CVE-2020-8984

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

Mitigation only
Fix from $1,950 2020-03-24
Zend Framework MEDIUM 6.1
CVE-2015-3154

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attack…

Fix: 1.12.12 / 2.3.8+
Fix from $1,600 2020-01-27
Framework CRITICAL 9.8
CVE-2015-0270

Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

Fix: 2.2.10 / 2.3.5+
Fix from $2,300 2019-10-25
Zendto MEDIUM 6.1
CVE-2018-1000841

Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execu…

Fix: 5.15-1+
Fix from $1,600 2018-12-20
Zend Server MEDIUM 6.1
CVE-2018-10230

Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.

Fix: 9.1.3+
Fix from $1,600 2018-04-19
Zend Framework HIGH 7.5
CVE-2015-7503

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private …

Mitigation only
Fix from $1,950 2017-10-10
Diactoros MEDIUM 6.1
CVE-2015-3257

Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-s…

Fix: after 1.0.3
Fix from $1,600 2017-08-25
Zend Framework CRITICAL 9.1
CVE-2015-1555

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using s…

Mitigation only
Fix from $2,300 2017-08-07
Zend Framework HIGH 8.8
CVE-2015-1786

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

Mitigation only
Fix from $1,950 2017-06-08
Zend Framework CRITICAL 9.8
CVE-2016-10034EPSS 38%

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor…

Fix: after 2.4.10
Fix from $2,300 2016-12-30
Zend Framework MEDIUM 6.8
CVE-2015-5161EPSS 10%

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under P…

No fix yet
Fix from $1,600 2015-08-25
Zendopenid MEDIUM 6.4
CVE-2014-2684

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 d…

Fix: after 2.0.1
Fix from $1,600 2014-11-16
Zendrest MEDIUM 5.0
CVE-2014-2683

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer…

Fix: 1.12.4 / 2.1.6+
Fix from $1,600 2014-11-16
Zendrest MEDIUM 6.8
CVE-2014-2682

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer…

Fix: 1.12.4 / 2.1.6+
Fix from $1,600 2014-11-16
Zendrest MEDIUM 6.4
CVE-2014-2681

Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendSer…

Fix: 1.12.4 / 2.1.6+
Fix from $1,600 2014-11-16
Zend Framework MEDIUM 5.0
CVE-2014-8088

The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to …

Fix: after 1.12.7
Fix from $1,600 2014-10-22
Zend Framework HIGH 7.5
CVE-2014-2685

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 v…

Fix: after 2.0.1
Fix from $1,950 2014-09-04
Zend Framework MEDIUM 5.0
CVE-2012-5657

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attac…

Mitigation only
Fix from $1,600 2013-05-02
Zend Framework MEDIUM 6.4
CVE-2012-6531

(1) Zend_Dom, (2) Zend_Feed, and (3) Zend_Soap in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 do not properly handle SimpleXMLElement …

Mitigation only
Fix from $1,600 2013-02-13
Zend Framework MEDIUM 5.0
CVE-2012-6532

(1) Zend_Dom, (2) Zend_Feed, (3) Zend_Soap, and (4) Zend_XmlRpc in Zend Framework 1.x before 1.11.13 and 1.12.x before 1.12.0 allow remote attackers …

Mitigation only
Fix from $1,600 2013-02-13
Zend Server MEDIUM 6.0
CVE-2012-5382

Untrusted search path vulnerability in the installation functionality in Zend Server 5.6.0 SP4, when installed in the top-level C:\ directory, might …

No fix yet
Fix from $1,600 2012-10-11
Framework MEDIUM 5.0
CVE-2011-3825

Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reve…

Mitigation only
Fix from $1,600 2011-09-24
Framework MEDIUM 5.0
CVE-2009-4417

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages t…

Fix: after 1.9.6
Fix from $1,600 2009-12-24
Zend Platform MEDIUM 6.2
CVE-2007-1370

Zend Platform 2.2.3 and earlier has incorrect ownership for scd.sh and certain other files, which allows local users to gain root privileges by modif…

Patch available
Fix from $1,600 2007-03-09
Zend Framework Preview MEDIUM 6.8
CVE-2006-5900

Cross-site scripting (XSS) vulnerability in the incubator/tests/Zend/Http/_files/testRedirections.php sample code in Zend Framework Preview 0.2.0 all…

Mitigation only
Fix from $1,600 2006-11-15
Zend Platform HIGH 7.5
CVE-2006-4431

Multiple buffer overflows in the (a) Session Clustering Daemon and the (b) mod_cluster module in the Zend Platform 2.2.1 and earlier allow remote att…

Fix: after 2.2.1a
Fix from $1,950 2006-08-29