Zfaka Project maintains a file-sharing and digital goods platform with a focused product footprint centered on the eponymous Zfaka application, where observed vulnerabilities reflect foundational input-handling and file-upload control issues. The recurring weaknesses—SQL injection and unrestricted file uploads—are characteristic of web application flaws in content management and transaction systems; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zfaka Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22294CRITICAL A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foreground and add a background administrator account. | Jan 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24553CRITICAL An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution. | Feb 21, 2022 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zfaka Project.
Media articles that mention a CVE ID that affects a product developed by Zfaka Project — matched by CVE ID, not by vendor name.