Zendto

Vendor:

First CVE: Dec 28, 2013 · Active for 12 years

8
Total CVEs
More Total CVEs than 87% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 47% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Zendto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2013
12 years ago
Most Recent CVE
Apr 5, 2025
479 days ago

CVE Severity & Scoring

Zendto8 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High1 (12.5%)
Unknown1 (12.5%)
User Interaction
None4 (50.0%)
Unknown1 (12.5%)
Required3 (37.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (87.5%)
Unknown1 (12.5%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via she
Apr 5, 202510.046NONO
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with
Mar 24, 20209.830NONO
ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.
Mar 24, 20208.826NONO
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.
Mar 24, 20207.523NONO
ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.
Mar 2, 20216.120NONO
Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in
Dec 20, 20186.120NONO
Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr fiel
Dec 28, 20134.318NONO
A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords stored as MD5 hashes t
Apr 5, 20254.817NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Zendto

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.06-316.10.6%00
6.06-216.10.6%00
6.06-116.10.6%00
5.22-138.70.9%00
5.21-238.70.9%00
5.21-138.70.9%00
5.20-938.70.9%00
5.20-838.70.9%00
5.20-738.70.9%00
5.20-638.70.9%00
5.20-538.70.9%00
5.20-338.70.9%00
5.20-238.70.9%00
5.20-138.70.9%00
5.19-138.70.9%00
5.18-238.70.9%00
5.18-138.70.9%00
5.17-638.70.9%00
5.17-538.70.9%00
5.17-438.70.9%00