Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zentao

First CVE: Oct 27, 2023Active for: 3 yearsTotal CVEs: 9

Zentao is a modestly represented project-management and collaboration platform that has seen vulnerabilities cluster around its core product and related offerings. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through structural weaknesses in input handling and request validation—including path traversal, cross-site scripting, server-side request forgery, and cross-site request forgery—alongside issues with cleartext storage of sensitive data that are characteristic of web application architecture. Defenders should monitor this vendor's security advisories and treat exposed instances as a patching priority; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zentao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 27, 2023
2 years ago
Most Recent CVE
Feb 16, 2026
158 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-13787CRITICAL
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing ma
Nov 30, 20259.129NONO
CVE-2023-46375HIGH
ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).
Oct 27, 20238.823NONO
CVE-2025-13789MEDIUM
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in serve
Nov 30, 20255.320NONO
CVE-2023-46376HIGH
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
Oct 27, 20237.520NONO
CVE-2026-2552MEDIUM
A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of
Feb 16, 20265.518NONO
CVE-2026-2551MEDIUM
A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the component Backup Handler. This ma
Feb 16, 20265.418NONO
CVE-2023-46491MEDIUM
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.
Oct 27, 20236.118NONO
CVE-2023-46374MEDIUM
ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS).
Oct 27, 20236.118NONO
CVE-2026-1884MEDIUM
A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file module/webhook/model.php of the component Webhook Module. Th
Feb 4, 20264.917NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
67%
22%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low2 (22.2%)
High1 (11.1%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zentao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zentao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zentao's Products

View all 2 CNAs →

Top CWEs