Zerowdd's modestly sized vulnerability footprint centers on a narrow set of web-facing applications, including StudentManager and MyBlog, that handle user input and file uploads. The vulnerabilities affecting this vendor skew toward serious outcomes and recur through application-layer input-handling and access-control flaws—cross-site scripting, code injection, improper access control, and unrestricted file uploads—that reflect the architectural demands of dynamic web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zerowdd over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13191CRITICAL A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/ | Jan 8, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-13189CRITICAL A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The | Jan 8, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-3587HIGH A vulnerability classified as critical was found in ZeroWdd/code-projects studentmanager 1.0. This vulnerability affects unknown code of the file /getTeacherList. The manipulation | Apr 14, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-13134HIGH A vulnerability, which was classified as critical, was found in ZeroWdd studentmanager 1.0. Affected is the function addTeacher/editTeacher of the file src/main/Java/com/wdd/studen | Jan 5, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-13133HIGH A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/co | Jan 5, 2025 | 8.8 | 24 | NO | NO |
CVE-2026-2201MEDIUM A security vulnerability has been detected in ZeroWdd studentmanager up to 2151560fc0a50ec00426785ec1e01a3763b380d9. This impacts the function addLeave of the file src/main/java/co | Feb 9, 2026 | 5.4 | 19 | NO | NO |
CVE-2024-13192MEDIUM A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/Blo | Jan 8, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-13143MEDIUM A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/sy | Jan 6, 2025 | 5.4 | 17 | NO | NO |
CVE-2024-13142MEDIUM A vulnerability was found in ZeroWdd studentmanager 1.0. It has been declared as problematic. This vulnerability affects the function submitAddRole of the file src/main/java/com/ze | Jan 5, 2025 | 4.8 | 17 | NO | NO |
CVE-2023-39094MEDIUM Cross Site Scripting vulnerability in ZeroWdd studentmanager v.1.0 allows a remote attacker to execute arbitrary code via the username parameter in the student list function. | Aug 21, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zerowdd.
Media articles that mention a CVE ID that affects a product developed by Zerowdd — matched by CVE ID, not by vendor name.