Vulnerabilities > Zend > Zendto > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-02 | CVE-2021-27888 | Cross-site Scripting vulnerability in Zend Zendto ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. | 6.1 |
2018-12-20 | CVE-2018-1000841 | Cross-site Scripting vulnerability in Zend Zendto Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the victim's browser.. | 6.1 |