Zrlog is a modestly represented blogging and content-management platform whose vulnerability profile concentrates in a single product and skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring weaknesses center on web-application input handling and access control—cross-site scripting, SQL injection, unrestricted file upload, path traversal, and authorization flaws—that are characteristic of server-side PHP-based content systems. Defenders treating this as a self-hosted platform should prioritize input sanitization and access-control hardening alongside vendor updates; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zrlog over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44093CRITICAL A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell | Nov 28, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-45872CRITICAL zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter. | Jul 1, 2025 | 9.8 | 30 | NO | NO |
CVE-2020-27514CRITICAL Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial o | Aug 11, 2023 | 9.1 | 28 | NO | NO |
CVE-2021-44094HIGH ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file | Nov 28, 2021 | 7.8 | 25 | NO | NO |
CVE-2018-17420HIGH An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter. | Mar 7, 2019 | 7.2 | 24 | NO | NO |
CVE-2018-17079MEDIUM An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area. | Jun 19, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-17421MEDIUM An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname. | Mar 7, 2019 | 6.1 | 21 | NO | NO |
CVE-2020-21052MEDIUM Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function. | Jun 20, 2023 | 6.1 | 20 | NO | NO |
CVE-2020-18066MEDIUM Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment. | Jun 29, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-21316MEDIUM A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cooki | Jun 15, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zrlog.
Media articles that mention a CVE ID that affects a product developed by Zrlog — matched by CVE ID, not by vendor name.