← Back

Zrlog

zrlog

Vendor: Zrlog • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zrlog
1Zrlog
Aug 14, 2025
Jul 1, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.
1Zrlog
1Zrlog
Nov 21, 2024
Aug 11, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).
1Zrlog
1Zrlog
Dec 10, 2024
Jun 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.
1Zrlog
1Zrlog
Nov 21, 2024
Nov 28, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
1Zrlog
1Zrlog
Nov 21, 2024
Nov 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell
1Zrlog
1Zrlog
Nov 21, 2024
Jun 29, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.
1Zrlog
1Zrlog
Nov 21, 2024
Jun 15, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain a...Show more
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.Show less
1Zrlog
1Zrlog
Nov 21, 2024
Aug 25, 2020
N/A· v4
5.7 MEDIUM· v3
3.5 LOW· v2
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.
1Zrlog
1Zrlog
Nov 21, 2024
Sep 20, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.
1Zrlog
1Zrlog
Nov 21, 2024
Jun 19, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
1Zrlog
1Zrlog
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
1Zrlog
1Zrlog
Nov 21, 2024
Mar 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.