« Back to list

Zhao-github

Zhao-github Apiadmin: vulnerabilities and CVEs

Zhao-github Apiadmin has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-71622High (7.4)0.45%—Sep 4, 2026
SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component
CVE-2026-71620High (8.1)0.61%—Sep 4, 2026
File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1203 Exploitation for Client Execution1
  3. T1210 Exploitation of Remote Services1
  4. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.