Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Zrlog CRITICAL 9.8
CVE-2025-45872

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

Mitigation only
Fix from $2,300 2025-07-01
Zrlog CRITICAL 9.1
CVE-2020-27514

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbit…

No fix yet
Fix from $2,300 2023-08-11
Zrlog MEDIUM 6.1
CVE-2020-21052

Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/a…

No fix yet
Fix from $1,600 2023-06-20
Zrlog CRITICAL 9.8
CVE-2021-44093

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the…

No fix yet
Fix from $2,300 2021-11-28
Zrlog HIGH 7.8
CVE-2021-44094

ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

No fix yet
Fix from $1,950 2021-11-28
Zrlog MEDIUM 6.1
CVE-2020-18066

Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.

No fix yet
Fix from $1,600 2021-06-29
Zrlog MEDIUM 5.4
CVE-2019-16643

An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.

No fix yet
Fix from $1,600 2019-09-20
Zrlog MEDIUM 6.1
CVE-2018-17079

An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.

No fix yet
Fix from $1,600 2019-06-19
Zrlog HIGH 7.2
CVE-2018-17420

An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.

No fix yet
Fix from $1,950 2019-03-07
Zrlog MEDIUM 6.1
CVE-2018-17421

An issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.

No fix yet
Fix from $1,600 2019-03-07