Zblogcn maintains Z-Blog PHP, a web content management system deployed across a modestly sized user base that punches above its volume in the vulnerability landscape. Vulnerabilities affecting this product skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency to acquire public exploit code, reflecting the appeal of CMS platforms as targets for both targeted and opportunistic attack. The exposure recurs through a characteristic set of web-application weakness classes: cross-site scripting, cross-site request forgery, code injection, and sensitive information disclosure, patterns endemic to server-side template engines and user-input handling in PHP-based platforms. Defenders should treat Z-Blog PHP installations as requiring active monitoring and prompt patching, particularly in internet-exposed deployments; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zblogcn over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7737MEDIUM In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vul | Mar 6, 2018 | 5.3 | 32 | NO | YES |
CVE-2018-7736MEDIUM In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability | Mar 6, 2018 | 6.1 | 32 | NO | YES |
CVE-2022-40357CRITICAL A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote a | Sep 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2018-19463HIGH zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_syste | Nov 22, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-18842HIGH CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code. | Oct 30, 2018 | 8.8 | 27 | NO | NO |
CVE-2024-55529CRITICAL Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template. | Jan 6, 2025 | 9.8 | 26 | NO | NO |
CVE-2018-8893HIGH Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code. | Mar 31, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-29176HIGH An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file. | Dec 2, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-18268MEDIUM Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php." | Jun 7, 2021 | 6.1 | 25 | NO | YES |
CVE-2018-9153HIGH The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because o | Apr 16, 2018 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zblogcn.
Media articles that mention a CVE ID that affects a product developed by Zblogcn — matched by CVE ID, not by vendor name.