Browse all 3 CVE security advisories affecting zinoui. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2026-4132 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters — HTTP HeadersCWE-73 | 7.2 | High | 2026-04-22 |
| CVE-2026-2717 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values — HTTP HeadersCWE-93 | 5.5 | Medium | 2026-04-22 |
| CVE-2026-1379 | HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting — HTTP HeadersCWE-79 | 4.4 | Medium | 2026-04-22 |
This page lists every published CVE security advisory associated with zinoui. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.