Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Authentication Bypass Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2948) CVE-2015-2948 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2949) CVE-2015-2949 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5592) CVE-2015-5592 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5593) CVE-2015-5593 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5594) CVE-2015-5594 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20140) CVE-2018-20140 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5592) CVE-2020-5592 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-44449) CVE-2022-44449 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-5593) CVE-2020-5593 CWE-138 CWE-138 High Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2007-6666) CVE-2007-6666 CWE-138 CWE-138 High Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4564) CVE-2009-4564 CWE-138 CWE-138 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4566) CVE-2009-4566 CWE-138 CWE-138 High Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4906) CVE-2010-4906 CWE-138 CWE-138 High Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-0994) CVE-2012-0994 CWE-138 CWE-138 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-7242) CVE-2013-7242 CWE-138 CWE-138 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-5591) CVE-2015-5591 CWE-138 CWE-138 High Zenphoto Improper Privilege Management Vulnerability (CVE-2018-0610) CVE-2018-0610 CWE-269 CWE-269 High Zenphoto Other Vulnerability (CVE-2006-2186) CVE-2006-2186 Medium Zenphoto Other Vulnerability (CVE-2006-2187) CVE-2006-2187 Medium Zenphoto Other Vulnerability (CVE-2007-0616) CVE-2007-0616 High Zenphoto Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-36079) CVE-2020-36079 CWE-434 CWE-434 High Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-4729) CVE-2010-4729 CWE-352 CWE-352 Medium Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0535) CVE-2011-0535 CWE-352 CWE-352 Medium Zikula Cryptographic Issues Vulnerability (CVE-2010-4728) CVE-2010-4728 Medium Zikula Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-2293) CVE-2014-2293 CWE-94 CWE-94 Critical Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1724) CVE-2010-1724 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-0911) CVE-2011-0911 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-3352) CVE-2011-3352 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-3979) CVE-2011-3979 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-6168) CVE-2013-6168 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2016-9835) CVE-2016-9835 CWE-138 CWE-138 Critical Zimbra Collaboration Suite SSRF (CVE-2020-7796) CVE-2020-7796 CWE-918 CWE-918 High Zimbra Collaboration XSS (CVE-2022-27926) CVE-2022-27926 CWE-79 CWE-79 Medium ZK Framework AuUploader Information Disclosure (CVE-2022-36537) CVE-2022-36537 CWE-200 CWE-200 High Zope Web Application Server Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2012-5507) CVE-2012-5507 CWE-362 CWE-362 Medium Zope Web Application Server Cryptographic Issues Vulnerability (CVE-2012-6661) CVE-2012-6661 Medium Zope Web Application Server CVE-2011-2528 Vulnerability (CVE-2011-2528) CVE-2011-2528 High Zope Web Application Server CVE-2011-3587 Vulnerability (CVE-2011-3587) CVE-2011-3587 Critical Zope Web Application Server Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-41050) CVE-2023-41050 CWE-200 CWE-200 High Zope Web Application Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-32633) CVE-2021-32633 CWE-22 CWE-22 High Zope Web Application Server Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-32674) CVE-2021-32674 CWE-22 CWE-22 High Zope Web Application Server Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability (CVE-2021-32811) CVE-2021-32811 CWE-915 CWE-915 High Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-5145) CVE-2009-5145 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1104) CVE-2010-1104 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4924) CVE-2011-4924 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42458) CVE-2023-42458 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44389) CVE-2023-44389 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) (CVE-2021-33507) CVE-2021-33507 CWE-707 CWE-707 Medium Zope Web Application Server Other Vulnerability (CVE-2000-0062) CVE-2000-0062 Critical Zope Web Application Server Other Vulnerability (CVE-2000-0483) CVE-2000-0483 High Zope Web Application Server Other Vulnerability (CVE-2000-0725) CVE-2000-0725 High Zope Web Application Server Other Vulnerability (CVE-2000-1211) CVE-2000-1211 High Zope Web Application Server Other Vulnerability (CVE-2000-1212) CVE-2000-1212 Medium Zope Web Application Server Other Vulnerability (CVE-2001-0567) CVE-2001-0567 Medium Zope Web Application Server Other Vulnerability (CVE-2001-1227) CVE-2001-1227 High Zope Web Application Server Other Vulnerability (CVE-2001-1278) CVE-2001-1278 High Zope Web Application Server Other Vulnerability (CVE-2002-0170) CVE-2002-0170 High Zope Web Application Server Other Vulnerability (CVE-2002-0687) CVE-2002-0687 Medium Zope Web Application Server Other Vulnerability (CVE-2002-0688) CVE-2002-0688 High Zope Web Application Server Other Vulnerability (CVE-2005-3323) CVE-2005-3323 High Zope Web Application Server Other Vulnerability (CVE-2006-3458) CVE-2006-3458 Low Zope Web Application Server Other Vulnerability (CVE-2006-4684) CVE-2006-4684 Medium Zope Web Application Server Other Vulnerability (CVE-2007-0240) CVE-2007-0240 Medium Zope Web Application Server Other Vulnerability (CVE-2010-3198) CVE-2010-3198 Medium Zope Web Application Server Other Vulnerability (CVE-2012-5486) CVE-2012-5486 Medium Zope Web Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5489) CVE-2012-5489 CWE-264 CWE-264 Medium Zope Web Application Server Resource Management Errors Vulnerability (CVE-2008-5102) CVE-2008-5102 Medium [Possible] AWStats Detected CWE-538 CWE-538 Medium [Possible] Backup Folder CWE-538 CWE-538 Medium [Possible] Backup Source Code Detected CWE-538 CWE-538 High [Possible] Database Connection String Detected CWE-200 CWE-200 Medium [Possible] Internal IP Address Disclosure CWE-200 CWE-200 Low [Possible] Internal Path Disclosure (*nix) CWE-200 CWE-200 Informational [Possible] Internal Path Disclosure (Windows) CWE-200 CWE-200 Informational [Possible] Password Transmitted over Query String CWE-200 CWE-200 Medium 1...291292293 292 / 293