Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zend

First CVE: Aug 29, 2006Active for: 20 yearsTotal CVEs: 48
39.6
VTI Score
Medium

Zend's vulnerability footprint spans a small number of web framework and application-platform products that have been widely embedded across PHP-based enterprise and development environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposure inherent to web-facing frameworks and server platforms. The exposure recurs across products such as Zend Framework, ZendTo, and Zend Platform through web-tier weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and unsafe deserialization of untrusted data—flaws that are characteristic of server-side application and framework codebases. Defenders should inventory PHP deployments running these products and prioritize framework and server patches; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zend over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 29, 2006
19 years ago
Most Recent CVE
Apr 5, 2025
475 days ago

Products(21 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3007CRITICAL
Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, rel
Jan 4, 20219.881NOYES
CVE-2012-3363CRITICAL
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files o
Feb 13, 20139.165NOYES
CVE-2016-10034CRITICAL
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote att
Dec 30, 20169.864NOYES
CVE-2021-47667CRITICAL
An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via she
Apr 5, 202510.046NONO
CVE-2011-1939CRITICAL
SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6.
Nov 26, 20199.843NOYES
CVE-2014-8089CRITICAL
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arb
Feb 17, 20209.832NONO
CVE-2020-29312CRITICAL
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as
Apr 4, 20239.831NONO
CVE-2015-0270CRITICAL
Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.
Oct 25, 20199.831NONO
CVE-2014-4914CRITICAL
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecif
Dec 29, 20179.831NONO
CVE-2016-6233CRITICAL
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use
Feb 17, 20179.831NONO
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
52%
17%
31%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network27 (56.3%)
Unknown20 (41.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (56.3%)
High1 (2.1%)
Unknown20 (41.7%)
User Interaction
None19 (39.6%)
Unknown20 (41.7%)
Required9 (18.8%)
Privileges Required
Low1 (2.1%)
High0 (0.0%)
None27 (56.3%)
Unknown20 (41.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.2% of CVEs· 95th percentile
ExploitDB
6 CVEs
12.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zend.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zend — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zend's Products

View all 5 CNAs →

Top CWEs