ZeroHour

Vulnerabilities

33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22679
Unauthenticated RCE in Weaver E-cology 10.0

Weaver (Fanwei) E-cology 10.0, a widely used Chinese enterprise OA/collaboration platform, contains a critical unauthenticated remote code execution vulnerability (CVSS 4.0: 9.3, CWE-306 missing authentication) in the /papi/esearch/data/devops/dubboApi/debug/method endpoint. An attacker triggers it by sending a crafted POST request with attacker-controlled interfaceName and methodName parameters, which invokes exposed debug functionality and reaches command-execution helpers without any credentials. Successful exploitation yields arbitrary command execution on the underlying system, enabling full server compromise. Organizations running E-cology 10.0 builds released before the 20260312 (March 12, 2026) update are affected. Exploitation has already been observed in the wild — the Shadowserver Foundation first detected scanning/exploitation on 2026-03-31 (UTC) — and EPSS puts the 30-day exploitation probability at 20.4% (97th percentile), though there is no public PoC and the flaw is not yet in CISA KEV.

Do: Upgrade E-cology 10.0 to the 20260312 build or later immediately. Until patched, restrict internet exposure of /papi/ endpoints (especially /papi/esearch/data/devops/dubboApi/debug/method) via firewall/WAF rules, and review access logs for POST requests to that endpoint to check for exploitation since 2026-03-31.

9.320%
  • Weaver (Fanwei) E-cology 10.0 versions prior to 20260312
largetens of thousands of deployments plausibly affected (order of magnitude 10k–100k); exact count unknown
CVE-2025-34038
A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint.

A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a database query within the getSelectAllIds(sql, type) method, reachable through the cmd=getSelectAllId workflow in the AjaxManager. This allows unauthenticated attackers to execute arbitrary SQL queries, potentially exposing sensitive data such as administrator password hashes. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

NVD description · AI analysis pending
8.72% PoC ×2
  • weaver e-cology
CVE-2024-48070
+3 in the same advisory: …48072 …48069 …48071
An issue in Weaver E-cology v.

An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges

NVD description · AI analysis pending
9.8
group max
<1%
  • weaver e-cology
CVE-2024-7704
A vulnerability was found in Weaver e-cology 8.

A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the component Source Code Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.9<1% PoC
  • weaver e-cology
CVE-2024-4939
The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and incl

The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • weavertheme weaver xtreme theme support
CVE-2024-3227
A vulnerability was found in Panwei eoffice OA up to 9.5.

A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/theme_set/save_image.php of the component Backend. The manipulation of the argument image_type leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259072.

NVD description · AI analysis pending
7.2<1% PoC
  • weaver e-office
CVE-2023-51892
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.

An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.

NVD description · AI analysis pending
9.8<1%
  • weaver e-cology
CVE-2023-6990
The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insuf

The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied meta (page-head-code). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • weavertheme weaver xtreme theme support
CVE-2023-4971
The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues whe

The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

NVD description · AI analysis pending
7.2<1% PoC
  • weavertheme weaver xtreme theme support
CVE-2023-34798
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

NVD description · AI analysis pending
9.8<1%
  • weaver e-office
CVE-2023-3793
A vulnerability was found in Weaver e-cology.

A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownloadForOutDoc.class of the component HTTP POST Request Handler. The manipulation of the argument fileid with the input 1+WAITFOR+DELAY leads to sql injection. Upgrading to version 10.58.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-235061 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • weaver e-cology
CVE-2023-1404
The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up

The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1.6. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • weavertheme weaver show posts
CVE-2023-1403
The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, a

The Weaver Xtreme Theme for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 5.0.7. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

NVD description · AI analysis pending
5.4<1%
  • weavertheme weaver xtreme theme
CVE-2023-2806
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0.

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipulation leads to xml external entity reference. The associated identifier of this vulnerability is VDB-229411. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
8.8<1% PoC
  • weaver e-cology
CVE-2023-2766
+1 in the same advisory: …2765
A vulnerability was found in Weaver OA 9.5 and classified as problematic.

A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
7.554% PoC
  • weaver e-office
CVE-2023-2648
+1 in the same advisory: …2647
A vulnerability was found in Weaver E-Office 9.5.

A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-228777 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
9.8
group max
28% PoC
  • weaver e-office
CVE-2023-0276
The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a pag

The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

NVD description · AI analysis pending
5.4<1% PoC
  • weavertheme weaver xtreme theme support
CVE-2021-29031
A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/users_import.php URI.

A cross-site scripting (XSS) vulnerability in Bitweaver version 3.1.0 allows remote attackers to inject JavaScript via the /users/admin/users_import.php URI.

NVD description · AI analysis pending
4.8<1% PoC
  • bitweaver bitweaver
CVE-2019-16133
An issue was discovered in eteams OA v4.0.34.

An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.

NVD description · AI analysis pending
6.51% PoC
  • weaver eteams oa
CVE-2019-10272
An issue was discovered in Weaver e-cology 9.0.

An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isintervenor parameter, as demonstrated by the %0aSet-cookie: substring.

NVD description · AI analysis pending
6.1<1% PoC
  • weaver e-cology