VendorsEasycorpzentaoall versions
Vulnerabilities

Easycorp Zentao

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-24216
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
Published 2024-02-08 · Modified
9.8EPSS 0.013
CVE-2020-28165
The EasyCorp ZenTao PMS 12.4.2 application suffers from an arbitrary file upload vulnerability. An attacker can upload arbitrary webshell to the server by using the downloadZipPackage() function.
Published 2021-08-12 · Modified
9.8EPSS 0.011
CVE-2024-24202
An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Published 2024-02-08 · Modified
9.8EPSS 0.010
CVE-2025-5114
easysoft zentaopms Editor index.php edit deserialization
Published 2025-05-23 · Analyzed
9.1EPSS 0.005
CVE-2021-27556
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
Published 2021-08-31 · Modified
9.0EPSS 0.040
CVE-2022-47745
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
Published 2023-01-19 · Modified
8.8EPSS 0.154
CVE-2023-44827
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.
Published 2023-10-10 · Modified
8.8EPSS 0.009
CVE-2022-37700
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
Published 2022-09-19 · Modified
7.5EPSS 0.031
CVE-2021-27558
A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via various areas such as data-link-creator.
Published 2021-08-31 · Modified
6.1EPSS 0.008
CVE-2023-6439
ZenTao PMS cross site scripting
Published 2023-11-30 · Modified
6.1EPSS 0.007
CVE-2020-21268
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
Published 2023-06-20 · Modified
6.1EPSS 0.006
CVE-2020-22533
Cross Site Scripting vulnerability found in Zentao allows a remote attacker to execute arbitrary code via the lang parameter
Published 2023-04-04 · Modified
6.1EPSS 0.005
CVE-2023-49394
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
Published 2024-01-10 · Modified
6.1EPSS 0.004
CVE-2023-46475
A Stored Cross-Site Scripting vulnerability was discovered in ZenTao 18.3 where a user can create a project, and in the name field of the project, they can inject malicious JavaScript code.
Published 2023-11-02 · Modified
5.4EPSS 0.004
CVE-2023-44826
Cross Site Scripting vulnerability in ZenTaoPMS v.18.6 allows a local attacker to obtain sensitive information via a crafted script.
Published 2023-10-10 · Modified
5.4EPSS 0.004
CVE-2021-27557
A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to update the fields of a Cron job.
Published 2021-08-31 · Modified
4.3EPSS 0.004