CVE-2025-13787Medium· 5.4▾ SunlitA flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper privilege management. It is possible to launch the attack remotely. Upgrading to version 21.7.7 is sufficient to fix this issue. You should upgrade the affected component.
zentao < 21.7.7Upgrade past the affected range:
zentao 21.7.7Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13789Medium· 6.3A vulnerability was found in ZenTao up to 21.7.6-8564
CVE-2026-94425High· 8.8A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150
CVE-2026-94048Medium· 6.6A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0
CVE-2026-94047Medium· 6.3A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32
CVE-2026-93968Low· 3.8A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1
CVE-2026-63349High· 7.0AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio