Skip to content
Noroxi

EasyCorp records

18 published records for vendor easycorp.

All records

18 records
  • ZenTao Pro Command Injection

    HighCVSS 8.8WeaponizedEPSS 17%

    easycorp · zentao proAug 6, 2020

  • ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.

    HighCVSS 8.8No exploitEPSS 15%

    easycorp · zentaoJan 19, 2023

  • Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/m

    CriticalCVSS 9.8No exploitEPSS 1%

    easycorp · zentaoFeb 8, 2024

  • The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    easycorp · zentaoAug 12, 2021

  • An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 al

    CriticalCVSS 9.8No exploitEPSS 1%

    easycorp · zentaoFeb 8, 2024

  • An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execu

    HighCVSS 8.8No exploitEPSS 1%

    easycorp · zentaoOct 9, 2023

  • Zentao Demo15 is vulnerable to Directory Traversal.

    HighCVSS 7.5No exploitEPSS 3%

    easycorp · zentaoSep 19, 2022

  • The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type par

    HighCVSS 7.2No exploitEPSS 4%

    easycorp · zentaoAug 30, 2021

  • A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such

    MediumCVSS 6.1No exploitEPSS 1%

    easycorp · zentaoAug 30, 2021

  • CVE-2023-6439
    24Monitor

    ZenTao PMS cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    easycorp · zentaoNov 30, 2023

  • Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parame

    MediumCVSS 6.1No exploitEPSS 1%

    easycorp · zentaoJun 20, 2023

  • Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter

    MediumCVSS 6.1No exploitEPSS 1%

    easycorp · zentaoApr 4, 2023

  • Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

    MediumCVSS 6.1No exploitEPSS 0%

    easycorp · zentaoJan 10, 2024

  • CVE-2024-3081
    21Monitor

    EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    easycorp · easyadminMar 29, 2024

  • CVE-2025-5114
    21Monitor

    easysoft zentaopms Editor index.php edit deserialization

    MediumCVSS 5.3No exploitEPSS 1%

    easycorp · zentaoMay 23, 2025

  • A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the pr

    MediumCVSS 5.4No exploitEPSS 0%

    easycorp · zentaoNov 2, 2023

  • Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.

    MediumCVSS 5.4No exploitEPSS 0%

    easycorp · zentaoOct 9, 2023

  • A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a C

    MediumCVSS 4.3No exploitEPSS 0%

    easycorp · zentaoAug 30, 2021