CVE-2024-55529
- EPSS 0.75%
- Veröffentlicht 06.01.2025 18:15:22
- Zuletzt bearbeitet 05.09.2025 00:27:20
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
CVE-2024-39203
- EPSS 8%
- Veröffentlicht 08.07.2024 16:15:08
- Zuletzt bearbeitet 13.03.2025 13:15:40
A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-40357
- EPSS 2.49%
- Veröffentlicht 20.09.2022 21:15:11
- Zuletzt bearbeitet 28.05.2025 16:15:28
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injec...
CVE-2020-29177
- EPSS 0.35%
- Veröffentlicht 02.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:23:46
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
CVE-2020-29176
- EPSS 0.39%
- Veröffentlicht 02.12.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 05:23:46
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
CVE-2020-18268
- EPSS 6.99%
- Veröffentlicht 07.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:08:31
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
CVE-2020-23352
- EPSS 0.24%
- Veröffentlicht 27.01.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:13:46
Z-BlogPHP 1.6.0 Valyria is affected by incorrect access control. PHP loose comparison and a magic hash can be used to bypass authentication. zb_user/plugin/passwordvisit/include.php:passwordvisit_input_password() uses loose comparison to authenticate...
CVE-2018-19556
- EPSS 0.25%
- Veröffentlicht 26.11.2018 07:29:01
- Zuletzt bearbeitet 21.11.2024 03:58:09
zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability
CVE-2018-19463
- EPSS 1.17%
- Veröffentlicht 22.11.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:58
zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's position is "W...
CVE-2018-18842
- EPSS 0.22%
- Veröffentlicht 30.10.2018 06:29:01
- Zuletzt bearbeitet 21.11.2024 03:56:44
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.