CVE-2018-13980: Zeta-Producer Zeta Producer

Medium severity, CVSS 5.5. EPSS: 6.9% chance of exploitation in the next 30 days.

The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

Affected products

Published 2018-07-16. Last modified 2026-06-17.