Zetacomponents maintains a small portfolio centered on mail and MVC-framework tools, with a vulnerability profile anchored to application-layer control-flow and code-generation issues such as hidden functionality and code injection. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zetacomponents over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15806HIGH The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, wh | Nov 15, 2017 | 8.1 | 42 | NO | YES |
CVE-2023-24108CRITICAL MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attacker | Feb 22, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zetacomponents.
Media articles that mention a CVE ID that affects a product developed by Zetacomponents — matched by CVE ID, not by vendor name.