Zeeways develops a focused line of web-based business applications including job portals, property listings, and e-commerce platforms, with a consistent vulnerability signal centered on application-layer input-handling and authentication weaknesses such as SQL injection, cross-site scripting, improper authentication, and insufficient input validation. Despite modest volume, these products sit in a prominent niche within web-application vulnerability tracking and frequently acquire public exploit code, making timely patching essential for deployed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zeeways over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6912HIGH Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php. | Aug 7, 2009 | 7.5 | 31 | NO | YES |
CVE-2008-5042HIGH Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admin/home.php. | Nov 12, 2008 | 7.5 | 29 | NO | YES |
CVE-2019-25636HIGH Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET paramete | Mar 24, 2026 | 8.2 | 28 | NO | NO |
CVE-2008-5782HIGH SQL injection vulnerability in bannerclick.php in ZeeMatri 3.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Dec 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4717HIGH SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Oct 23, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3706HIGH SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | Aug 19, 2008 | 7.5 | 28 | NO | YES |
CVE-2019-25635HIGH Zeeways Matrimony CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the profile_list endpoint. Attacke | Mar 24, 2026 | 8.2 | 27 | NO | NO |
CVE-2008-6914MEDIUM Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executa | Aug 7, 2009 | 6.5 | 26 | NO | YES |
CVE-2008-6913MEDIUM Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an exec | Aug 7, 2009 | 6.5 | 26 | NO | YES |
CVE-2010-2144MEDIUM Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter | Jun 3, 2010 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zeeways.
Media articles that mention a CVE ID that affects a product developed by Zeeways — matched by CVE ID, not by vendor name.