Vulnerabilities > Easycorp > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-10 | CVE-2023-44827 | Command Injection vulnerability in Easycorp Zentao, Zentao BIZ and Zentao MAX An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function. | 8.8 |
2023-01-19 | CVE-2022-47745 | SQL Injection vulnerability in Easycorp Zentao ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. | 8.8 |
2022-09-19 | CVE-2022-37700 | Path Traversal vulnerability in Easycorp Zentao 15.0 Zentao Demo15 is vulnerable to Directory Traversal. | 7.5 |