Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Arbitrary File Creation Authentication Bypass Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial-of-service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilitie Known Vulnerabilities Ldap Injection Malware Missing Update Privilege Escalation Remote Code Execution SSRF SSTI Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity ZenCart Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4322) CVE-2009-4322 CWE-200 CWE-200 Medium ZenCart Improper Authentication Vulnerability (CVE-2009-2255) CVE-2009-2255 CWE-287 CWE-287 Medium ZenCart Improper Input Validation Vulnerability (CVE-2009-4321) CVE-2009-4321 CWE-20 CWE-20 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4547) CVE-2011-4547 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4567) CVE-2011-4567 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-0882) CVE-2015-0882 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-6578) CVE-2020-6578 CWE-707 CWE-707 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2005-3996) CVE-2005-3996 CWE-138 CWE-138 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6985) CVE-2008-6985 CWE-138 CWE-138 Medium ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2008-6986) CVE-2008-6986 CWE-138 CWE-138 Medium Zenphoto Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5595) CVE-2015-5595 CWE-352 CWE-352 Medium Zenphoto Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-0993) CVE-2012-0993 CWE-94 CWE-94 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2008-6925) CVE-2008-6925 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-4562) CVE-2009-4562 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-4563) CVE-2009-4563 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-4907) CVE-2010-4907 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-0995) CVE-2012-0995 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-2641) CVE-2012-2641 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-4519) CVE-2012-4519 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-7241) CVE-2013-7241 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2948) CVE-2015-2948 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-2949) CVE-2015-2949 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5592) CVE-2015-5592 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5593) CVE-2015-5593 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-5594) CVE-2015-5594 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-20140) CVE-2018-20140 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-5592) CVE-2020-5592 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-44449) CVE-2022-44449 CWE-707 CWE-707 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4564) CVE-2009-4564 CWE-138 CWE-138 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-0994) CVE-2012-0994 CWE-138 CWE-138 Medium Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2013-7242) CVE-2013-7242 CWE-138 CWE-138 Medium Zenphoto Other Vulnerability (CVE-2006-2186) CVE-2006-2186 Medium Zenphoto Other Vulnerability (CVE-2006-2187) CVE-2006-2187 Medium Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2010-4729) CVE-2010-4729 CWE-352 CWE-352 Medium Zikula Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-0535) CVE-2011-0535 CWE-352 CWE-352 Medium Zikula Cryptographic Issues Vulnerability (CVE-2010-4728) CVE-2010-4728 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1724) CVE-2010-1724 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-0911) CVE-2011-0911 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-3352) CVE-2011-3352 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-3979) CVE-2011-3979 CWE-707 CWE-707 Medium Zikula Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2013-6168) CVE-2013-6168 CWE-707 CWE-707 Medium Zimbra Collaboration XSS (CVE-2022-27926) CVE-2022-27926 CWE-79 CWE-79 Medium Zope Web Application Server Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2012-5507) CVE-2012-5507 CWE-362 CWE-362 Medium Zope Web Application Server Cryptographic Issues Vulnerability (CVE-2012-6661) CVE-2012-6661 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2009-5145) CVE-2009-5145 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2010-1104) CVE-2010-1104 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-4924) CVE-2011-4924 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-42458) CVE-2023-42458 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-44389) CVE-2023-44389 CWE-707 CWE-707 Medium Zope Web Application Server Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) (CVE-2021-33507) CVE-2021-33507 CWE-707 CWE-707 Medium Zope Web Application Server Other Vulnerability (CVE-2000-1212) CVE-2000-1212 Medium Zope Web Application Server Other Vulnerability (CVE-2001-0567) CVE-2001-0567 Medium Zope Web Application Server Other Vulnerability (CVE-2002-0687) CVE-2002-0687 Medium Zope Web Application Server Other Vulnerability (CVE-2006-4684) CVE-2006-4684 Medium Zope Web Application Server Other Vulnerability (CVE-2007-0240) CVE-2007-0240 Medium Zope Web Application Server Other Vulnerability (CVE-2010-3198) CVE-2010-3198 Medium Zope Web Application Server Other Vulnerability (CVE-2012-5486) CVE-2012-5486 Medium Zope Web Application Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5489) CVE-2012-5489 CWE-264 CWE-264 Medium Zope Web Application Server Resource Management Errors Vulnerability (CVE-2008-5102) CVE-2008-5102 Medium [Possible] AWStats Detected CWE-538 CWE-538 Medium [Possible] Backup Folder CWE-538 CWE-538 Medium [Possible] Database Connection String Detected CWE-200 CWE-200 Medium [Possible] Password Transmitted over Query String CWE-200 CWE-200 Medium [Possible] Source Code Disclosure (Ruby) CWE-540 CWE-540 Medium 1...9596979899 99 / 99