digitalzoomstudio records
11 published records for vendor digitalzoomstudio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 9.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-502 Deserialization of Untrusted Data2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-73 External Control of File Name or Path1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2021-39316Proof of concept | ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosuredigitalzoomstudio · zoomsounds · CWE-22 | High7.5 | — | 65.8% | Aug 31, 2021 |
41Plan | CVE-2021-4449Proof of concept | ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Uploaddigitalzoomstudio · zoomsounds · CWE-434 | Critical9.8 | — | 5.4% | Oct 16, 2024 |
40Plan | CVE-2015-9471No exploit | The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.digitalzoomstudio · zoomsounds · CWE-434 | Critical9.8 | — | 4.0% | Oct 10, 2019 |
39Monitor | CVE-2024-13777No exploit | ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injectiondigitalzoomstudio · zoomsounds · CWE-502 | Critical9.8 | — | 0.6% | Mar 5, 2025 |
39Monitor | CVE-2025-47568No exploit | WordPress ZoomSounds plugin <= 6.91 - PHP Object Injection vulnerabilitydigitalzoomstudio · zoomsounds · CWE-502 | Critical9.8 | — | 0.5% | May 23, 2025 |
36Monitor | CVE-2021-4457No exploit | ZoomSounds < 6.05 - Unauthenticated Arbitrary File Uploaddigitalzoomstudio · zoomsounds · CWE-434 | Critical9.1 | — | 0.4% | Jun 25, 2025 |
32Monitor | CVE-2024-13776No exploit | ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipudigitalzoomstudio · zoomsounds · CWE-862 | High8.1 | — | 0.3% | Apr 5, 2025 |
30Monitor | CVE-2025-3431No exploit | ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Downloaddigitalzoomstudio · zoomsounds · CWE-73 | High7.5 | — | 0.4% | Apr 8, 2025 |
21Monitor | CVE-2025-0839No exploit | ZoomSounds <= 6.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodedigitalzoomstudio · zoomsounds · CWE-79 | Medium5.4 | — | 0.2% | Apr 5, 2025 |
19Monitor | CVE-2014-9094Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin fordigitalzoomstudio · video gallery · CWE-79 | Medium4.3 | — | 7.3% | Nov 26, 2014 |
17Monitor | CVE-2014-3923No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackedigitalzoomstudio · video gallery · CWE-79 | Medium4.3 | — | 1.6% | May 30, 2014 |
- CVE-2021-3931650Plan
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
HighCVSS 7.5Proof of conceptEPSS 66%digitalzoomstudio · zoomsoundsAug 31, 2021
- CVE-2021-444941Plan
ZoomSounds <= 5.96 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8Proof of conceptEPSS 5%digitalzoomstudio · zoomsoundsOct 16, 2024
- CVE-2015-947140Plan
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
CriticalCVSS 9.8No exploitEPSS 4%digitalzoomstudio · zoomsoundsOct 10, 2019
- CVE-2024-1377739Monitor
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection
CriticalCVSS 9.8No exploitEPSS 1%digitalzoomstudio · zoomsoundsMar 5, 2025
- CVE-2025-4756839Monitor
WordPress ZoomSounds plugin <= 6.91 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 1%digitalzoomstudio · zoomsoundsMay 23, 2025
- CVE-2021-445736Monitor
ZoomSounds < 6.05 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.1No exploitEPSS 0%digitalzoomstudio · zoomsoundsJun 25, 2025
- CVE-2024-1377632Monitor
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update and Settings Manipu
HighCVSS 8.1No exploitEPSS 0%digitalzoomstudio · zoomsoundsApr 5, 2025
- CVE-2025-343130Monitor
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated Arbitrary File Download
HighCVSS 7.5No exploitEPSS 0%digitalzoomstudio · zoomsoundsApr 8, 2025
- CVE-2025-083921Monitor
ZoomSounds <= 6.91 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%digitalzoomstudio · zoomsoundsApr 5, 2025
- CVE-2014-909419Monitor
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for
MediumCVSS 4.3Proof of conceptEPSS 7%digitalzoomstudio · video galleryNov 26, 2014
- CVE-2014-392317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attacke
MediumCVSS 4.3No exploitEPSS 2%digitalzoomstudio · video galleryMay 30, 2014