zend
Security Risk Profile
40
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 48 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 29, 2006 to present
48
Total CVEs
24
Critical+High
0
Exploited
8
Unpatched
Threat Assessment
Avg CVSS
7.3
Base severity
Avg EPSS
1%
Exploit probability
Unpatched
8
Critical/High
Risk Level
40/100
medium
Severity Distribution
Critical
14High
10Medium
24Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
XSS
10
2
SQL Injection
7
3
XEE
7
4
Infoleak
3
5
Command Injection
2
Most Affected Products
1. Zend ZendTo396
2. VMware Spring Framework344
3. Zend Zend Framework211
4. Zend Framework64
5. PHP PHP59
Recent Vulnerabilities
See more →CVE-2025-5952
CVSS 7.5EPSS 2%high
Zend.To NSSDropoff.php exec os command injection
6/10/2025🔧 No Patch
CVE-2024-9129
CVSS 9.3EPSS 0%critical
Format String Injection in Zend Server
10/22/2024🔧 No Patch
CVE-2020-29312
CVSS 9.8critical
4/4/2023🔧 No Patch
CVE-2021-27888
CVSS 6.1medium
3/2/2021🔧 No Patch
CVE-2021-3007
CVSS 9.8critical
1/4/2021
CVE-2020-8986
CVSS 9.8critical
3/24/2020🔧 No Patch
CVE-2020-8985
CVSS 8.8high
3/24/2020🔧 No Patch
CVE-2020-8984
CVSS 7.5high
3/24/2020🔧 No Patch
CVE-2014-4913
CVSS 6.1medium
12/15/2019
CVE-2011-1939
CVSS 9.8critical
11/26/2019
Monitor zend in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.