Vulnerability Name CVE Severity
XWiki Improper Privilege Management Vulnerability (CVE-2023-26475) CVE-2023-26475
XWiki Improper Privilege Management Vulnerability (CVE-2023-34465) CVE-2023-34465
XWiki Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2023-26476) CVE-2023-26476
XWiki Improper Restriction of XML External Entity Reference Vulnerability (CVE-2023-27480) CVE-2023-27480
XWiki Incomplete Cleanup Vulnerability (CVE-2023-36468) CVE-2023-36468
XWiki Incorrect Authorization Vulnerability (CVE-2023-32069) CVE-2023-32069
XWiki Incorrect Authorization Vulnerability (CVE-2023-46244) CVE-2023-46244
XWiki Incorrect Use of Privileged APIs Vulnerability (CVE-2022-24821) CVE-2022-24821
XWiki Missing Authorization Vulnerability (CVE-2022-36091) CVE-2022-36091
XWiki Missing Authorization Vulnerability (CVE-2022-41930) CVE-2022-41930
XWiki Missing Authorization Vulnerability (CVE-2022-41937) CVE-2022-41937
XWiki Missing Authorization Vulnerability (CVE-2023-37910) CVE-2023-37910
XWiki Missing Authorization Vulnerability (CVE-2024-43401) CVE-2024-43401
XWiki Other Vulnerability (CVE-2022-36090) CVE-2022-36090
XWiki Other Vulnerability (CVE-2023-26478) CVE-2023-26478
XWiki Other Vulnerability (CVE-2023-29507) CVE-2023-29507
XWiki Out-of-bounds Write Vulnerability (CVE-2023-26470) CVE-2023-26470
XWikiplatform Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-66473) CVE-2025-66473
XWikiplatform Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-40104) CVE-2026-40104
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31986) CVE-2024-31986
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31988) CVE-2024-31988
XWikiplatform CVE-2025-48063 Vulnerability (CVE-2025-48063) CVE-2025-48063
XWikiplatform CVE-2025-55749 Vulnerability (CVE-2025-55749) CVE-2025-55749
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31465) CVE-2024-31465
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31984) CVE-2024-31984
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37899) CVE-2024-37899
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37901) CVE-2024-37901
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-55877) CVE-2024-55877
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-49581) CVE-2025-49581
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-51991) CVE-2025-51991
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-32968) CVE-2025-32968
XWikiplatform Improper Removal of Sensitive Information Before Storage or Transfer Vulnerability (CVE-2025-58049) CVE-2025-58049
XWikiplatform Incorrect Authorization Vulnerability (CVE-2024-55662) CVE-2024-55662
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-29924) CVE-2025-29924
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-49586) CVE-2025-49586
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-53836) CVE-2025-53836
XWikiplatform Incorrect Privilege Assignment Vulnerability (CVE-2025-49580) CVE-2025-49580
XWikiplatform Insertion of Sensitive Information Into Sent Data Vulnerability (CVE-2025-49584) CVE-2025-49584
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49582) CVE-2025-49582
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49585) CVE-2025-49585
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49587) CVE-2025-49587
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31981) CVE-2024-31981
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31983) CVE-2024-31983
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31987) CVE-2024-31987
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31997) CVE-2024-31997
XWikiplatform Missing Authorization Vulnerability (CVE-2024-55879) CVE-2024-55879
XWikiplatform Missing Authorization Vulnerability (CVE-2025-23025) CVE-2025-23025
XWiki Platform RCE (CVE-2023-37462) CVE-2023-37462
XWikiplatform Relative Path Traversal Vulnerability (CVE-2025-55748) CVE-2025-55748
XWiki Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-48240) CVE-2023-48240
XWiki Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2022-23619) CVE-2022-23619
YetiForce CRM Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-0269) CVE-2022-0269
YOURLS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-0088) CVE-2022-0088
YOURLS Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2021-3734) CVE-2021-3734
Zabbix 1.8.x-2.2.x Local File Inclusion via XXE Attack
Zabbix 2.0.8 SQL injection CVE-2013-5743
ZenCart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-11675) CVE-2017-11675
ZenCart Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2021-3291) CVE-2021-3291
ZenCart Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2254) CVE-2009-2254
ZenCart Inclusion of Functionality from Untrusted Control Sphere Vulnerability (CVE-2024-5762) CVE-2024-5762
ZenCart Other Vulnerability (CVE-2009-4323) CVE-2009-4323
Zend framework configuration file information disclosure
Zend Framework local file disclosure via XXE injection CVE-2012-3363 CVE-2015-5161
Zenphoto Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-5593) CVE-2020-5593
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2007-6666) CVE-2007-6666
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-4566) CVE-2009-4566
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2010-4906) CVE-2010-4906
Zenphoto Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-5591) CVE-2015-5591
Zenphoto Improper Privilege Management Vulnerability (CVE-2018-0610) CVE-2018-0610
Zenphoto Other Vulnerability (CVE-2007-0616) CVE-2007-0616
Zenphoto Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-36079) CVE-2020-36079
Zimbra Collaboration LFI (CVE-2025-68645) CVE-2025-68645
Zimbra Collaboration Suite SSRF (CVE-2020-7796) CVE-2020-7796
ZK Framework AuUploader Information Disclosure (CVE-2022-36537) CVE-2022-36537
Zope Web Application Server CVE-2011-2528 Vulnerability (CVE-2011-2528) CVE-2011-2528