zentao vulnerabilities
CVEs whose affected-version data names the zentao package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-13789Medium· 6.3A vulnerability was found in ZenTao up to 21.7.6-8564
A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remote…
▾ Sunlitzentao · zentaoEPSS 0.29%via NVD
CVE-2025-13787Medium· 5.4A flaw has been found in ZenTao up to 21.7.6-8564
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…
▾ Sunlitzentao · zentaoEPSS 0.38%via NVD