Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zblogcn

First CVE: Feb 6, 2018Active for: 8 yearsTotal CVEs: 22
36.4
VTI Score
Medium

Zblogcn maintains Z-Blog PHP, a web content management system deployed across a modestly sized user base that punches above its volume in the vulnerability landscape. Vulnerabilities affecting this product skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the appeal of CMS platforms as targets for both targeted and opportunistic attack. The exposure recurs through a characteristic set of web-application weakness classes: cross-site scripting, cross-site request forgery, code injection, and sensitive information disclosure, patterns endemic to server-side template engines and user-input handling in PHP-based platforms. Defenders should treat Z-Blog PHP installations as requiring active monitoring and prompt patching, particularly in internet-exposed deployments; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zblogcn over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2018
8 years ago
Most Recent CVE
Jan 6, 2025
567 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7737MEDIUM
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vul
Mar 6, 20185.332NOYES
CVE-2018-7736MEDIUM
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability
Mar 6, 20186.132NOYES
CVE-2022-40357CRITICAL
A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote a
Sep 20, 20229.830NONO
CVE-2018-19463HIGH
zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_syste
Nov 22, 20188.828NONO
CVE-2018-18842HIGH
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
Oct 30, 20188.827NONO
CVE-2024-55529CRITICAL
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
Jan 6, 20259.826NONO
CVE-2018-8893HIGH
Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.
Mar 31, 20188.826NONO
CVE-2020-29176HIGH
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
Dec 2, 20217.825NONO
CVE-2020-18268MEDIUM
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
Jun 7, 20216.125NOYES
CVE-2018-9153HIGH
The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because o
Apr 16, 20187.223NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
32%
14%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (40.9%)
Unknown0 (0.0%)
Required13 (59.1%)
Privileges Required
Low2 (9.1%)
High4 (18.2%)
None16 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.5% of CVEs· 95th percentile
ExploitDB
2 CVEs
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zblogcn.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zblogcn — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zblogcn's Products

View all 1 CNAs →

Top CWEs