Skip to main content

Vendor/product archive

zend / zendto CVEs

Beta · best-effort

6 CVEs tagged to zend / zendto1 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-27888

Published Mar 2, 2021

ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8986

Published Mar 24, 2020

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-8985

Published Mar 24, 2020

ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8984

Published Mar 24, 2020

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000841

Published Dec 20, 2018

Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code i…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6808

Published Dec 28, 2013

Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr fie…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1