Zendto
Vendor:
First CVE: Dec 28, 2013 · Active for 12 years
8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Zendto over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2013
12 years ago
Most Recent CVE
Apr 5, 2025
479 days ago
CVE Severity & Scoring
Zendto8 CVEs
50%
25%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High1 (12.5%)
Unknown1 (12.5%)
User Interaction
None4 (50.0%)
Unknown1 (12.5%)
Required3 (37.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (87.5%)
Unknown1 (12.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47667CRITICAL An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via she | Apr 5, 2025 | 10.0 | 46 | NO | NO |
CVE-2020-8986CRITICAL lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with | Mar 24, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-8985HIGH ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality. | Mar 24, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-8984HIGH lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header. | Mar 24, 2020 | 7.5 | 23 | NO | NO |
CVE-2021-27888MEDIUM ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. | Mar 2, 2021 | 6.1 | 20 | NO | NO |
CVE-2018-1000841MEDIUM Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in | Dec 20, 2018 | 6.1 | 20 | NO | NO |
CVE-2013-6808MEDIUM Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr fiel | Dec 28, 2013 | 4.3 | 18 | NO | NO |
CVE-2025-32352MEDIUM A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes t | Apr 5, 2025 | 4.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Zendto
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.06-3 | 1 | 6.1 | 0.6% | 0 | 0 |
| 6.06-2 | 1 | 6.1 | 0.6% | 0 | 0 |
| 6.06-1 | 1 | 6.1 | 0.6% | 0 | 0 |
| 5.22-1 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.21-2 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.21-1 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-9 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-8 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-7 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-6 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-5 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-3 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-2 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.20-1 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.19-1 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.18-2 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.18-1 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.17-6 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.17-5 | 3 | 8.7 | 0.9% | 0 | 0 |
| 5.17-4 | 3 | 8.7 | 0.9% | 0 | 0 |