Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ZealousWeb — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting ZealousWeb. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ZealousWeb develops web applications primarily for e-commerce platforms and content management systems. Historically, their products have been vulnerable to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation and insecure authentication mechanisms. The company has addressed multiple critical flaws over time, with seven CVEs documented in their public record. While no major security breaches have been widely reported, their consistent vulnerability pattern suggests a need for stronger security-by-design practices. ZealousWeb's applications typically require regular patching to mitigate risks, particularly for RCE flaws that could allow attackers to execute arbitrary code on affected servers.

CVE ID Title CVSS Severity Published
CVE-2026-73386 WordPress Track Geolocation Of Users Using Contact Form 7 plugin <= 3.0.2 - Sensitive Data Exposure vulnerability — Track Geolocation Of Users Using Contact Form 7 CWE-201 7.5 High 2026-08-19
CVE-2026-39707 WordPress Accept PayPal Payments using Contact Form 7 plugin <= 4.0.4 - Broken Access Control vulnerability — Accept PayPal Payments using Contact Form 7 CWE-862 5.3 Medium 2026-04-08
CVE-2025-53322 WordPress Accept Authorize.NET Payments Using Contact Form 7 plugin <= 2.5 - Sensitive Data Exposure Vulnerability — Accept Authorize.NET Payments Using Contact Form 7 CWE-201 5.3 Medium 2025-06-27
CVE-2025-53309 WordPress Accept Stripe Payments Using Contact Form 7 plugin <= 3.0 - Sensitive Data Exposure Vulnerability — Accept Stripe Payments Using Contact Form 7 CWE-201 5.3 Medium 2025-06-27
CVE-2025-52817 WordPress Abandoned Contact Form 7 plugin <= 2.2 - Broken Access Control vulnerability — Abandoned Contact Form 7 CWE-862 8.2 High 2025-06-27
CVE-2025-32679 WordPress User Registration Using Contact Form 7 plugin <= 2.4 - Cross Site Request Forgery (CSRF) vulnerability — User Registration Using Contact Form 7 CWE-352 5.4 Medium 2025-04-09
CVE-2024-37555 WordPress Generate PDF using Contact Form 7 plugin <= 4.1.2 - CSRF to Arbitrary File Upload vulnerability — Generate PDF using Contact Form 7 CWE-434 9.6 Critical 2024-07-09
CVE-2023-49188 WordPress Track Geolocation Of Users Using Contact Form 7 Plugin <= 2.0 is vulnerable to Cross Site Scripting (XSS) — Track Geolocation Of Users Using Contact Form 7 CWE-79 5.9 Medium 2023-12-15

This page lists every published CVE security advisory associated with ZealousWeb. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.