EasyCorp records
18 published records for vendor easycorp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.6%
- Pre-auth RCE
- 5
- With a fix record
- 5.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-7361Weaponized | ZenTao Pro Command Injectioneasycorp · zentao pro · CWE-78 | High8.8 | — | 17.2% | Aug 6, 2020 |
40Plan | CVE-2022-47745No exploit | ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.easycorp · zentao · CWE-89 | High8.8 | — | 15.4% | Jan 19, 2023 |
39Monitor | CVE-2024-24216No exploit | Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/measycorp · zentao · CWE-77 | Critical9.8 | — | 1.3% | Feb 8, 2024 |
39Monitor | CVE-2020-28165No exploit | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.easycorp · zentao · CWE-434 | Critical9.8 | — | 1.1% | Aug 12, 2021 |
39Monitor | CVE-2024-24202No exploit | An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 aleasycorp · zentao · CWE-434 | Critical9.8 | — | 1.0% | Feb 8, 2024 |
35Monitor | CVE-2023-44827No exploit | An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execueasycorp · zentao · CWE-77 | High8.8 | — | 0.9% | Oct 9, 2023 |
31Monitor | CVE-2022-37700No exploit | Zentao Demo15 is vulnerable to Directory Traversal.easycorp · zentao · CWE-22 | High7.5 | — | 3.1% | Sep 19, 2022 |
29Monitor | CVE-2021-27556No exploit | The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type pareasycorp · zentao · CWE-78 | High7.2 | — | 4.0% | Aug 30, 2021 |
24Monitor | CVE-2021-27558No exploit | A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such easycorp · zentao · CWE-79 | Medium6.1 | — | 0.8% | Aug 30, 2021 |
24Monitor | CVE-2023-6439No exploit | ZenTao PMS cross site scriptingeasycorp · zentao · CWE-79 | Medium6.1 | — | 0.7% | Nov 30, 2023 |
24Monitor | CVE-2020-21268No exploit | Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameeasycorp · zentao · CWE-79 | Medium6.1 | — | 0.6% | Jun 20, 2023 |
24Monitor | CVE-2020-22533No exploit | Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parametereasycorp · zentao · CWE-79 | Medium6.1 | — | 0.5% | Apr 4, 2023 |
24Monitor | CVE-2023-49394No exploit | Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.easycorp · zentao · CWE-601 | Medium6.1 | — | 0.4% | Jan 10, 2024 |
21Monitor | CVE-2024-3081No exploit | EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scriptingeasycorp · easyadmin · CWE-79 | Medium5.4 | — | 0.5% | Mar 29, 2024 |
21Monitor | CVE-2025-5114No exploit | easysoft zentaopms Editor index.php edit deserializationeasycorp · zentao · CWE-20 | Medium5.3 | — | 0.5% | May 23, 2025 |
21Monitor | CVE-2023-46475No exploit | A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the preasycorp · zentao · CWE-79 | Medium5.4 | — | 0.4% | Nov 2, 2023 |
21Monitor | CVE-2023-44826No exploit | Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.easycorp · zentao · CWE-79 | Medium5.4 | — | 0.4% | Oct 9, 2023 |
17Monitor | CVE-2021-27557No exploit | A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Ceasycorp · zentao · CWE-352 | Medium4.3 | — | 0.4% | Aug 30, 2021 |
- CVE-2020-736140Plan
ZenTao Pro Command Injection
HighCVSS 8.8WeaponizedEPSS 17%easycorp · zentao proAug 6, 2020
- CVE-2022-4774540Plan
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.
HighCVSS 8.8No exploitEPSS 15%easycorp · zentaoJan 19, 2023
- CVE-2024-2421639Monitor
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/m
CriticalCVSS 9.8No exploitEPSS 1%easycorp · zentaoFeb 8, 2024
- CVE-2020-2816539Monitor
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%easycorp · zentaoAug 12, 2021
- CVE-2024-2420239Monitor
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 al
CriticalCVSS 9.8No exploitEPSS 1%easycorp · zentaoFeb 8, 2024
- CVE-2023-4482735Monitor
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execu
HighCVSS 8.8No exploitEPSS 1%easycorp · zentaoOct 9, 2023
- CVE-2022-3770031Monitor
Zentao Demo15 is vulnerable to Directory Traversal.
HighCVSS 7.5No exploitEPSS 3%easycorp · zentaoSep 19, 2022
- CVE-2021-2755629Monitor
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type par
HighCVSS 7.2No exploitEPSS 4%easycorp · zentaoAug 30, 2021
- CVE-2021-2755824Monitor
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such
MediumCVSS 6.1No exploitEPSS 1%easycorp · zentaoAug 30, 2021
- CVE-2023-643924Monitor
ZenTao PMS cross site scripting
MediumCVSS 6.1No exploitEPSS 1%easycorp · zentaoNov 30, 2023
- CVE-2020-2126824Monitor
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parame
MediumCVSS 6.1No exploitEPSS 1%easycorp · zentaoJun 20, 2023
- CVE-2020-2253324Monitor
Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter
MediumCVSS 6.1No exploitEPSS 1%easycorp · zentaoApr 4, 2023
- CVE-2023-4939424Monitor
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
MediumCVSS 6.1No exploitEPSS 0%easycorp · zentaoJan 10, 2024
- CVE-2024-308121Monitor
EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scripting
MediumCVSS 5.4No exploitEPSS 1%easycorp · easyadminMar 29, 2024
- CVE-2025-511421Monitor
easysoft zentaopms Editor index.php edit deserialization
MediumCVSS 5.3No exploitEPSS 1%easycorp · zentaoMay 23, 2025
- CVE-2023-4647521Monitor
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the pr
MediumCVSS 5.4No exploitEPSS 0%easycorp · zentaoNov 2, 2023
- CVE-2023-4482621Monitor
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
MediumCVSS 5.4No exploitEPSS 0%easycorp · zentaoOct 9, 2023
- CVE-2021-2755717Monitor
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a C
MediumCVSS 4.3No exploitEPSS 0%easycorp · zentaoAug 30, 2021