Zend's vulnerability footprint spans a small number of web framework and application-platform products that have been widely embedded across PHP-based enterprise and development environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposure inherent to web-facing frameworks and server platforms. The exposure recurs across products such as Zend Framework, ZendTo, and Zend Platform through web-tier weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and unsafe deserialization of untrusted data—flaws that are characteristic of server-side application and framework codebases. Defenders should inventory PHP deployments running these products and prioritize framework and server patches; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zend over time
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3007CRITICAL Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, rel | Jan 4, 2021 | 9.8 | 81 | NO | YES |
CVE-2012-3363CRITICAL Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files o | Feb 13, 2013 | 9.1 | 65 | NO | YES |
CVE-2016-10034CRITICAL The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote att | Dec 30, 2016 | 9.8 | 64 | NO | YES |
CVE-2021-47667CRITICAL An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via she | Apr 5, 2025 | 10.0 | 46 | NO | NO |
CVE-2011-1939CRITICAL SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. | Nov 26, 2019 | 9.8 | 43 | NO | YES |
CVE-2014-8089CRITICAL SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arb | Feb 17, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-29312CRITICAL An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as | Apr 4, 2023 | 9.8 | 31 | NO | NO |
CVE-2015-0270CRITICAL Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter. | Oct 25, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-4914CRITICAL The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecif | Dec 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-6233CRITICAL The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use | Feb 17, 2017 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zend.
Media articles that mention a CVE ID that affects a product developed by Zend — matched by CVE ID, not by vendor name.