Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Zorem — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting Zorem. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Zorem is a network monitoring solution primarily deployed for infrastructure visibility and performance analysis. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from insufficient input validation and access controls. The product has faced multiple critical vulnerabilities affecting its web interface and API endpoints, with several instances allowing unauthenticated attackers to execute arbitrary commands or access sensitive system information. While no major public security incidents have been widely documented, the consistent presence of high-severity flaws in its CVE history suggests ongoing challenges in secure development practices, particularly in input handling and authentication mechanisms.

CVE ID Title CVSS Severity Published
CVE-2026-57773 WordPress Advanced Shipment Tracking for WooCommerce plugin <= 4.0 - SQL Injection vulnerability — Advanced Shipment Tracking for WooCommerce CWE-89 7.6 High 2026-07-13
CVE-2024-31283 WordPress Advanced Local Pickup for WooCommerce plugin <=1.6.2 - Broken Access Control vulnerability — Advanced Local Pickup for WooCommerce CWE-862 7.5 High 2024-06-09
CVE-2024-32814 WordPress Advanced Local Pickup for WooCommerce plugin <= 1.6.1 - Broken Access Control vulnerability — Advanced Local Pickup for WooCommerce CWE-862 5.3 Medium 2024-06-09
CVE-2022-40702 WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control — Advanced Local Pickup for WooCommerce CWE-862 5.4 Medium 2024-01-17
CVE-2022-38141 WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control — Sales Report Email for WooCommerce CWE-862 4.3 Medium 2024-01-17
CVE-2023-2841 Advanced Local Pickup for WooCommerce <= 1.5.5 - Authenticated (Administrator+) SQL Injection — Zorem Local Pickup CWE-89 7.2 High 2023-11-22
CVE-2021-4347 Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change — Advanced Shipment Tracking for WooCommerce CWE-862 9.9 Critical 2023-06-07
CVE-2022-41635 WordPress Advanced Shipment Tracking for WooCommerce Plugin <= 3.5.2 is vulnerable to Cross Site Request Forgery (CSRF) — Advanced Shipment Tracking for WooCommerce CWE-352 4.3 Medium 2023-05-25

This page lists every published CVE security advisory associated with Zorem. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.