Skip to main content

Vendor archive

zend CVEs

Beta · best-effort

45 CVEs tagged to vendor zend13 Critical, 8 High, 24 Medium, 0 Low, 0 Unrated.

CVE-2020-29312

Published Apr 4, 2023

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27888

Published Mar 2, 2021

ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3007

Published Jan 4, 2021

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, re…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2020-8986

Published Mar 24, 2020

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8985

Published Mar 24, 2020

ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8984

Published Mar 24, 2020

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3154

Published Jan 27, 2020

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP h…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0270

Published Oct 25, 2019

Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000841

Published Dec 20, 2018

Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4914

Published Dec 29, 2017

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspeci…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7503

Published Oct 10, 2017

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3257

Published Aug 25, 2017

Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open re…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1555

Published Aug 7, 2017

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1786

Published Jun 8, 2017

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6233

Published Feb 17, 2017

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4861

Published Feb 17, 2017

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to r…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10034

Published Dec 30, 2016

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote at…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-7695

Published Jun 7, 2016

The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-5723

Published Jun 7, 2016

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM befor…

CVSS 7.8 · High

CVE-2015-5161

Published Aug 25, 2015

The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environme…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 45 CVEsPage 1 of 2