CVE-2026-30285: Zora

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.

Affected products

  • Zora Zora: version 2.60.0 only

Published 2026-03-31. Last modified 2026-07-24.