Skip to main content

Vendor/product archive

zend / framework CVEs

Beta · best-effort

3 CVEs tagged to zend / framework1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2015-0270

Published Oct 25, 2019

Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3825

Published Sep 24, 2011

Zend Framework 1.11.3 in Zend Server CE 5.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4417

Published Dec 24, 2009

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via ve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1