Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zblogcn z-blogphp vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2018-10680
Z-BlogPHP 1.5.2 has a stored Cross Site Scripting Vulnerability exploitable by an administrator who navigates to "Web site settings --> Basic setting --> Website title" and enters an XSS payload via the zb_system/cmd.php ZC_BLOG_NAME parameter. NOTE: the vendor di...
Zblogcn Z-blogphp 1.5.2
605
VMScore
CVE-2018-8893
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.
Zblogcn Z-blogphp 1.5.1
505
VMScore
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability
Zblogcn Z-blogphp 1.5.1.1740
1 EDB exploit
578
VMScore
CVE-2018-9153
The plugin upload component in Z-BlogPHP 1.5.1 allows remote malicious users to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The componen...
Zblogcn Z-blogphp 1.5.1
516
VMScore
CVE-2018-6656
Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
Zblogcn Z-blogphp 1.5.1
445
VMScore
CVE-2020-23352
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate, which can be bypassed via ma...
Zblogcn Z-blogphp 1.6.0
605
VMScore
CVE-2020-29176
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows malicious users to execute arbitrary code via a crafted JPG file.
Zblogcn Z-blogphp 1.6.1.2100
570
VMScore
CVE-2020-29177
Z-BlogPHP v1.6.1.2100 exists to contain an arbitrary file deletion vulnerability via \app_del.php.
Zblogcn Z-blogphp 1.6.1.2100
605
VMScore
CVE-2018-18842
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote malicious users to execute arbitrary PHP code.
Zblogcn Z-blogphp 1.5.2.1935(zero)
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2