ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-45317
+4 in the same advisory: …45316 …45314 …45313 …45315
A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive.

A zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a crafted archive.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • hortusfox hortusfox
CVE-2024-57329
HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function.

HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize or escape user inputs, allowing attackers to inject and execute arbitrary JavaScript payloads.

NVD description · AI analysis pending
5.4<1% PoC
  • hortusfox hortusfox