CVE-2026-6650 is an unrestricted file upload vulnerability in Z-BlogPHP version 1.7.5, specifically within the App::UnPack function of the ZBA File Handler component located at /zb_users/plugin/AppCentre/app_upload.php. This vulnerability allows attackers to upload files without proper restrictions, potentially leading to unauthorized code execution or system compromise. The vulnerability presents a medium severity risk with a CVSS score of 4.7. It requires network access and can be exploited by authenticated users with high privileges, but demands no user interaction. The impact is limited to confidentiality, integrity, and availability of affected systems, though the consequences could extend beyond the application itself depending on deployment context and file permissions. Exploitation is currently possible, as public exploit code is available and the vulnerability is actively tracked on security advisory lists. However, the vulnerability shows low community attention relative to other CVEs, with an EPSS score indicating minimal prevalence in real-world exploitation attempts at this time. The vendor has not responded to disclosure communications, suggesting patches may not be forthcoming through official channels.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Z-BlogPHP | 1.7.5CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.