Title |
Severity |
Exploit |
Date |
Affected Version |
Zendframework URL Rewrite vulnerability
|
Medium
|
|
Jun 7, 2024
|
< 2.5.0
|
ZendFramework vulnerable to Cross-site Scripting
|
Medium
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.0.1
|
ZendFramework potential remote code execution in zend-mail via Sendmail adapter
|
Medium
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.4.11
|
ZendFramework Potential Proxy Injection Vulnerabilities
|
Medium
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.0.5
|
ZendFramework Information Disclosure and Insufficient Entropy vulnerability
|
Medium
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.4.9
|
ZendFramework SQL injection due to execution of platform-specific SQL containing interpolations
|
High
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4
|
Zendframework vulnerable to XXE/XEE attacks
|
Critical
|
|
Jun 7, 2024
|
>= 2.1.0 < 2.1.6
>= 2.2.0 < 2.2.6
|
ZendFramework Potential Information Disclosure and Insufficient Entropy vulnerabilities
|
High
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4
|
Zendframework session validation vulnerability
|
Medium
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.2.9
>= 2.3.0 < 2.3.4
|
ZendFramework Route Parameter Injection Via Query String in `Zend\Mvc`
|
High
|
|
Jun 7, 2024
|
>= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4
|