Product
zrlog
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-45872
CVE-2020-27514
CVE-2020-21052
CVE-2021-44094
CVE-2021-44093
CVE-2020-18066
CVE-2020-21316
CVE-2020-19005
CVE-2019-16643
CVE-2018-17079
CVE-2018-17421
CVE-2018-17420
all versions
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
all versions
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attack
all versions
Cross Site Scripting vulnerability in zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame param
all versions
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
all versions
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the origina
all versions
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
all versions
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject a
all versions
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download t
all versions
An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.
all versions
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
all versions
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
all versions
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywor