Zomp maintains a narrowly focused product portfolio centered on the ZompLog logging platform, which processes user-supplied input for display and analysis. The durable signal in its vulnerability profile centers on application-layer input-handling weaknesses, specifically cross-site scripting and code-injection flaws that arise from improper neutralization and generation of dynamic content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zomp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53888HIGH Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attacke | Dec 15, 2025 | 8.8 | 28 | NO | NO |
CVE-2008-2349HIGH Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.php with the admin parameter se | May 20, 2008 | 7.5 | 28 | NO | YES |
CVE-2023-53887MEDIUM Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image s | Dec 15, 2025 | 5.4 | 20 | NO | NO |
CVE-2008-2176MEDIUM Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote attackers to inject arbitrary web script or HTML via the catname parameter. | May 13, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zomp.
Media articles that mention a CVE ID that affects a product developed by Zomp — matched by CVE ID, not by vendor name.