296,772
Total vulnerabilities in the database
Many Zend Framework 2 view helpers were using the escapeHtml() view helper in order to escape HTML attributes, instead of the more appropriate escapeHtmlAttr(). In situations where user data and/or JavaScript is used to seed attributes, this can lead to potential cross site scripting (XSS) attack vectors.
Vulnerable view helpers include:
Zend\Form view helpers.Zend\Navigation (aka Zend\View\Helper\Navigation\*) view helpers.htmlFlash(), htmlPage(), htmlQuickTime().Zend\View\Helper\Gravatar| Software | From | Fixed in |
|---|---|---|
zendframework / zendframework
|
2.0.0 | 2.2.7 |
zendframework / zendframework
|
2.3.0 | 2.3.1 |