Zentao is a modestly represented project-management and collaboration platform that has seen vulnerabilities cluster around its core product and related offerings. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through structural weaknesses in input handling and request validation—including path traversal, cross-site scripting, server-side request forgery, and cross-site request forgery—alongside issues with cleartext storage of sensitive data that are characteristic of web application architecture. Defenders should monitor this vendor's security advisories and treat exposed instances as a patching priority; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zentao over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13787CRITICAL A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing ma | Nov 30, 2025 | 9.1 | 29 | NO | NO |
CVE-2023-46375HIGH ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF). | Oct 27, 2023 | 8.8 | 23 | NO | NO |
CVE-2025-13789MEDIUM A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in serve | Nov 30, 2025 | 5.3 | 20 | NO | NO |
CVE-2023-46376HIGH Zentao Biz version 8.7 and before is vulnerable to Information Disclosure. | Oct 27, 2023 | 7.5 | 20 | NO | NO |
CVE-2026-2552MEDIUM A vulnerability was identified in ZenTao up to 21.7.8. Affected by this issue is the function delete of the file editor/control.php of the component Committer. Such manipulation of | Feb 16, 2026 | 5.5 | 18 | NO | NO |
CVE-2026-2551MEDIUM A vulnerability was determined in ZenTao up to 21.7.8. Affected by this vulnerability is the function delete of the file editor/control.php of the component Backup Handler. This ma | Feb 16, 2026 | 5.4 | 18 | NO | NO |
CVE-2023-46491MEDIUM ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library. | Oct 27, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-46374MEDIUM ZenTao Enterprise Edition version 4.1.3 and before is vulnerable to Cross Site Scripting (XSS). | Oct 27, 2023 | 6.1 | 18 | NO | NO |
CVE-2026-1884MEDIUM A weakness has been identified in ZenTao up to 21.7.6-85642. The impacted element is the function fetchHook of the file module/webhook/model.php of the component Webhook Module. Th | Feb 4, 2026 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zentao.
Media articles that mention a CVE ID that affects a product developed by Zentao — matched by CVE ID, not by vendor name.