Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-52521 1 Zblogcn 1 Zblogphp 2026-08-03 N/A
A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.
CVE-2020-23327 1 Zblogcn 1 Zblogphp 2025-02-18 6.1 Medium
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.