Zdir is a narrowly scoped vendor with a focused product portfolio centered on its namesake directory service, where the durable signal involves memory-safety issues such as out-of-bounds writes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zdir over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66945CRITICAL A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outsid | Mar 3, 2026 | 9.1 | 26 | NO | NO |
CVE-2023-23314HIGH An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary code via a crafted .ssh file. | Jan 23, 2023 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zdir.
Media articles that mention a CVE ID that affects a product developed by Zdir — matched by CVE ID, not by vendor name.