Vulnerability Database

With exploit

zendframework / zendframework

Title Severity Exploit Date Affected Version
Zendframework URL Rewrite vulnerability Medium Jun 7, 2024 < 2.5.0
ZendFramework vulnerable to Cross-site Scripting Medium Jun 7, 2024 >= 2.0.0 < 2.0.1
ZendFramework potential remote code execution in zend-mail via Sendmail adapter Medium Jun 7, 2024 >= 2.0.0 < 2.4.11
ZendFramework Potential Proxy Injection Vulnerabilities Medium Jun 7, 2024 >= 2.0.0 < 2.0.5
ZendFramework Information Disclosure and Insufficient Entropy vulnerability Medium Jun 7, 2024 >= 2.0.0 < 2.4.9
ZendFramework SQL injection due to execution of platform-specific SQL containing interpolations High Jun 7, 2024 >= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4
Zendframework vulnerable to XXE/XEE attacks Critical Jun 7, 2024 >= 2.1.0 < 2.1.6
>= 2.2.0 < 2.2.6
ZendFramework Potential Information Disclosure and Insufficient Entropy vulnerabilities High Jun 7, 2024 >= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4
Zendframework session validation vulnerability Medium Jun 7, 2024 >= 2.0.0 < 2.2.9
>= 2.3.0 < 2.3.4
ZendFramework Route Parameter Injection Via Query String in `Zend\Mvc` High Jun 7, 2024 >= 2.0.0 < 2.0.8
>= 2.1.0 < 2.1.4