CVE-2025-50857

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload

Published 2026-02-26. Last modified 2026-06-17.