📦 Zentao

by Zentao

🔍 What is Zentao?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-2552

MEDIUM CVSS 5.5 Feb 16, 2026

This CVE describes a path traversal vulnerability in ZenTao's Committer component that allows attackers to delete arbitrary files by manipulating the filePath parameter. It affects ZenTao versions up ...

CVE-2026-2551

MEDIUM CVSS 5.4 Feb 16, 2026

A path traversal vulnerability in ZenTao's backup handler allows attackers to delete arbitrary files by manipulating the fileName parameter. This affects ZenTao installations up to version 21.7.8. Rem...

CVE-2026-1884

MEDIUM CVSS 4.7 Feb 4, 2026

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in ZenTao's Webhook Module. Attackers can exploit the fetchHook function to make the server send unauthorized requests to internal...

CVE-2025-13789

MEDIUM CVSS 6.3 Nov 30, 2025

This CVE describes a server-side request forgery (SSRF) vulnerability in ZenTao's AI module. Attackers can exploit the makeRequest function in module/ai/model.php to make the server send unauthorized ...

CVE-2025-13787

MEDIUM CVSS 5.4 Nov 30, 2025

This vulnerability in ZenTao's file handler allows attackers to manipulate file deletion operations through improper privilege management. Attackers can exploit this remotely to delete files they shou...