Zanfi Solutions maintains a small, focused product portfolio around content management and portal applications including Zanfi CMS Lite, AutoDealers CMS AutoOnline, and JAW Portal, serving niche web-hosting and dealership verticals. The vendor's vulnerabilities recur through application-layer input-handling weaknesses—particularly SQL injection and path traversal—that are characteristic of web-facing CMS and portal software, and frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zanfi Solutions over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4159HIGH SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter. | Sep 22, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4074HIGH SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | Sep 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4073HIGH SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action. | Sep 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4158MEDIUM Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fl | Sep 22, 2008 | 6.8 | 27 | NO | YES |
CVE-2004-2195MEDIUM PHP remote file inclusion vulnerability in index.php in Zanfi CMS lite 1.1 allows remote attackers to execute arbitrary PHP code via the inc parameter. | Dec 31, 2004 | 5.0 | 19 | NO | NO |
CVE-2004-2196MEDIUM Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) de | Dec 31, 2004 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zanfi Solutions.
Media articles that mention a CVE ID that affects a product developed by Zanfi Solutions — matched by CVE ID, not by vendor name.