EasyCorp kayıtları
easycorp üreticisine ait 18 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %5,6
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %5,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-20 Improper Input Validation1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
18 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-7361Silahlaştırılmış | ZenTao Pro Command Injectioneasycorp · zentao pro · CWE-78 | Yüksek8,8 | — | %17,2 | 6 Ağu 2020 |
40Planlayın | CVE-2022-47745İstismar yok | ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.easycorp · zentao · CWE-89 | Yüksek8,8 | — | %15,4 | 19 Oca 2023 |
39İzleyin | CVE-2024-24216İstismar yok | Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/measycorp · zentao · CWE-77 | Kritik9,8 | — | %1,3 | 8 Şub 2024 |
39İzleyin | CVE-2020-28165İstismar yok | The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.easycorp · zentao · CWE-434 | Kritik9,8 | — | %1,1 | 12 Ağu 2021 |
39İzleyin | CVE-2024-24202İstismar yok | An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 aleasycorp · zentao · CWE-434 | Kritik9,8 | — | %1,0 | 8 Şub 2024 |
35İzleyin | CVE-2023-44827İstismar yok | An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execueasycorp · zentao · CWE-77 | Yüksek8,8 | — | %0,9 | 9 Eki 2023 |
31İzleyin | CVE-2022-37700İstismar yok | Zentao Demo15 is vulnerable to Directory Traversal.easycorp · zentao · CWE-22 | Yüksek7,5 | — | %3,1 | 19 Eyl 2022 |
29İzleyin | CVE-2021-27556İstismar yok | The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type pareasycorp · zentao · CWE-78 | Yüksek7,2 | — | %4,0 | 30 Ağu 2021 |
24İzleyin | CVE-2021-27558İstismar yok | A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such easycorp · zentao · CWE-79 | Orta6,1 | — | %0,8 | 30 Ağu 2021 |
24İzleyin | CVE-2023-6439İstismar yok | ZenTao PMS cross site scriptingeasycorp · zentao · CWE-79 | Orta6,1 | — | %0,7 | 30 Kas 2023 |
24İzleyin | CVE-2020-21268İstismar yok | Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameeasycorp · zentao · CWE-79 | Orta6,1 | — | %0,6 | 20 Haz 2023 |
24İzleyin | CVE-2020-22533İstismar yok | Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parametereasycorp · zentao · CWE-79 | Orta6,1 | — | %0,5 | 4 Nis 2023 |
24İzleyin | CVE-2023-49394İstismar yok | Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.easycorp · zentao · CWE-601 | Orta6,1 | — | %0,4 | 10 Oca 2024 |
21İzleyin | CVE-2024-3081İstismar yok | EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scriptingeasycorp · easyadmin · CWE-79 | Orta5,4 | — | %0,5 | 29 Mar 2024 |
21İzleyin | CVE-2025-5114İstismar yok | easysoft zentaopms Editor index.php edit deserializationeasycorp · zentao · CWE-20 | Orta5,3 | — | %0,5 | 23 May 2025 |
21İzleyin | CVE-2023-46475İstismar yok | A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the preasycorp · zentao · CWE-79 | Orta5,4 | — | %0,4 | 2 Kas 2023 |
21İzleyin | CVE-2023-44826İstismar yok | Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.easycorp · zentao · CWE-79 | Orta5,4 | — | %0,4 | 9 Eki 2023 |
17İzleyin | CVE-2021-27557İstismar yok | A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Ceasycorp · zentao · CWE-352 | Orta4,3 | — | %0,4 | 30 Ağu 2021 |
- CVE-2020-736140Planlayın
ZenTao Pro Command Injection
YüksekCVSS 8,8SilahlaştırılmışEPSS %17easycorp · zentao pro6 Ağu 2020
- CVE-2022-4774540Planlayın
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection.
YüksekCVSS 8,8İstismar yokEPSS %15easycorp · zentao19 Oca 2023
- CVE-2024-2421639İzleyin
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/m
KritikCVSS 9,8İstismar yokEPSS %1easycorp · zentao8 Şub 2024
- CVE-2020-2816539İzleyin
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1easycorp · zentao12 Ağu 2021
- CVE-2024-2420239İzleyin
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 al
KritikCVSS 9,8İstismar yokEPSS %1easycorp · zentao8 Şub 2024
- CVE-2023-4482735İzleyin
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execu
YüksekCVSS 8,8İstismar yokEPSS %1easycorp · zentao9 Eki 2023
- CVE-2022-3770031İzleyin
Zentao Demo15 is vulnerable to Directory Traversal.
YüksekCVSS 7,5İstismar yokEPSS %3easycorp · zentao19 Eyl 2022
- CVE-2021-2755629İzleyin
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type par
YüksekCVSS 7,2İstismar yokEPSS %4easycorp · zentao30 Ağu 2021
- CVE-2021-2755824İzleyin
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such
OrtaCVSS 6,1İstismar yokEPSS %1easycorp · zentao30 Ağu 2021
- CVE-2023-643924İzleyin
ZenTao PMS cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1easycorp · zentao30 Kas 2023
- CVE-2020-2126824İzleyin
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parame
OrtaCVSS 6,1İstismar yokEPSS %1easycorp · zentao20 Haz 2023
- CVE-2020-2253324İzleyin
Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter
OrtaCVSS 6,1İstismar yokEPSS %1easycorp · zentao4 Nis 2023
- CVE-2023-4939424İzleyin
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
OrtaCVSS 6,1İstismar yokEPSS %0easycorp · zentao10 Oca 2024
- CVE-2024-308121İzleyin
EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1easycorp · easyadmin29 Mar 2024
- CVE-2025-511421İzleyin
easysoft zentaopms Editor index.php edit deserialization
OrtaCVSS 5,3İstismar yokEPSS %1easycorp · zentao23 May 2025
- CVE-2023-4647521İzleyin
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the pr
OrtaCVSS 5,4İstismar yokEPSS %0easycorp · zentao2 Kas 2023
- CVE-2023-4482621İzleyin
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
OrtaCVSS 5,4İstismar yokEPSS %0easycorp · zentao9 Eki 2023
- CVE-2021-2755717İzleyin
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a C
OrtaCVSS 4,3İstismar yokEPSS %0easycorp · zentao30 Ağu 2021