Home/Product/zrlog
Product

zrlog

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-45872
all versions
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
9.8CRITICAL
CVE-2020-27514
all versions
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attack
9.1CRITICAL
CVE-2020-21052
all versions
Cross Site Scripting vulnerability in zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame param
6.1MEDIUM
CVE-2021-44094
all versions
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
7.8HIGH
CVE-2021-44093
all versions
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the origina
9.8CRITICAL
CVE-2020-18066
all versions
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
6.1MEDIUM
CVE-2020-21316
all versions
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject a
6.1MEDIUM
CVE-2020-19005
all versions
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download t
5.7MEDIUM
CVE-2019-16643
all versions
An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.
5.4MEDIUM
CVE-2018-17079
all versions
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
6.1MEDIUM
CVE-2018-17421
all versions
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
6.1MEDIUM
CVE-2018-17420
all versions
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywor
7.2HIGH
threatengine.sh