CVE-2026-30285: Zora
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
Affected products
- Zora Zora: version 2.60.0 only
Published 2026-03-31. Last modified 2026-07-24.