CVE-2023-44827: Easycorp Zentao

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.

Affected products

  • Easycorp Zentao: up to and including 18.6
  • Easycorp Zentao Biz: up to and including 8.6
  • Easycorp Zentao Max: up to and including 4.7

Published 2023-10-10. Last modified 2026-06-17.