Zend / Zend Framework
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-29312 | An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been dispute… | CRITICAL | 9.8 | Apr 4, 2023 |
| CVE-2021-3007 | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content… | CRITICAL | 9.8 | Jan 4, 2021 |
| CVE-2014-8089 | SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote att… | CRITICAL | 9.8 | Feb 17, 2020 |
| CVE-2015-3154 | CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inj… | MEDIUM | 6.1 | Jan 27, 2020 |
| CVE-2012-4451 | Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unsp… | MEDIUM | 6.1 | Jan 3, 2020 |
| CVE-2014-4913 | ZF2014-03 has a potential cross site scripting vector in multiple view helpers | MEDIUM | 6.1 | Dec 15, 2019 |
| CVE-2011-1939 | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql… | CRITICAL | 9.8 | Nov 26, 2019 |
| CVE-2015-0270 | Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter. | CRITICAL | 9.8 | Oct 25, 2019 |
| CVE-2014-4914 | The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection… | CRITICAL | 9.8 | Dec 29, 2017 |
| CVE-2015-7503 | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key. | HIGH | 7.5 | Oct 10, 2017 |
| CVE-2015-1555 | Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session val… | CRITICAL | 9.1 | Aug 7, 2017 |
| CVE-2015-1786 | Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers. | HIGH | 8.8 | Jun 8, 2017 |
| CVE-2016-6233 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via ve… | CRITICAL | 9.8 | Feb 16, 2017 |
| CVE-2016-4861 | The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by lev… | CRITICAL | 9.8 | Feb 16, 2017 |
| CVE-2016-10034 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 m… | CRITICAL | 9.8 | Dec 30, 2016 |
| CVE-2015-7695 | The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands vi… | CRITICAL | 9.8 | Jun 7, 2016 |
| CVE-2015-5723 | Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.… | HIGH | 7.8 | Jun 7, 2016 |
| CVE-2015-5161 | The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in… | MEDIUM | 6.8 | Aug 25, 2015 |
| CVE-2014-2684 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not ve… | MEDIUM | 6.4 | Nov 16, 2014 |
| CVE-2014-2683 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirva… | MEDIUM | 5.0 | Nov 16, 2014 |
| CVE-2014-2682 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirva… | MEDIUM | 6.8 | Nov 16, 2014 |
| CVE-2014-2681 | Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirva… | MEDIUM | 6.4 | Nov 16, 2014 |
| CVE-2014-8088 | The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass aut… | MEDIUM | 5.0 | Oct 22, 2014 |
| CVE-2014-2685 | The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the… | HIGH | 7.5 | Sep 4, 2014 |
| CVE-2012-5657 | The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attackers to re… | MEDIUM | 5.0 | May 2, 2013 |
Showing 1 to 25 of 27 CVEs