Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-45872 zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter. Zrlog Mitigation only Fix from $2,3002025-07-01 CRITICAL 9.1 CVE-2020-27514 Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbit… Zrlog No fix yet Fix from $2,3002023-08-11 MEDIUM 6.1 CVE-2020-21052 Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/a… Zrlog No fix yet Fix from $1,6002023-06-20 CRITICAL 9.8 CVE-2021-44093 A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the… Zrlog No fix yet Fix from $2,3002021-11-28 HIGH 7.8 CVE-2021-44094 ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file Zrlog No fix yet Fix from $1,9502021-11-28 MEDIUM 6.1 CVE-2020-18066 Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment. Zrlog No fix yet Fix from $1,6002021-06-29 MEDIUM 6.1 CVE-2020-21316 A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script… Zrlog Patch available Fix from $1,6002021-06-15 MEDIUM 5.7 CVE-2020-19005 zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup … Zrlog Patch available Fix from $1,6002020-08-25 MEDIUM 5.4 CVE-2019-16643 An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area. Zrlog No fix yet Fix from $1,6002019-09-20 MEDIUM 6.1 CVE-2018-17079 An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area. Zrlog No fix yet Fix from $1,6002019-06-19 HIGH 7.2 CVE-2018-17420 An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter. Zrlog No fix yet Fix from $1,9502019-03-07 MEDIUM 6.1 CVE-2018-17421 An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname. Zrlog No fix yet Fix from $1,6002019-03-07