ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-45872
zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

NVD description · AI analysis pending
9.8<1% PoC
  • zrlog zrlog
CVE-2020-27514
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files

Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

NVD description · AI analysis pending
9.11% PoC
  • zrlog zrlog
CVE-2020-21052
Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment f

Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.

NVD description · AI analysis pending
6.1<1% PoC
  • zrlog zrlog
CVE-2021-44093
+1 in the same advisory: …44094
A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file t

A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell

NVD description · AI analysis pending
9.8
group max
3% PoC
  • zrlog zrlog
CVE-2020-18066
Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.

Cross Site Scripting vulnerability in ZrLog 2.1.0 via the (1) userName and (2) email parameters in post/addComment.

NVD description · AI analysis pending
6.1<1% PoC
  • zrlog zrlog
CVE-2020-21316
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen

A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.

NVD description · AI analysis pending
6.11%
  • zrlog zrlog
CVE-2020-19005
zrlog v2.1.0 has a vulnerability with the permission check.

zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.

NVD description · AI analysis pending
5.7<1%
  • zrlog zrlog
CVE-2019-16643
An issue was discovered in ZrLog 2.1.1.

An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.

NVD description · AI analysis pending
5.4<1% PoC
  • zrlog zrlog
CVE-2018-17079
An issue was discovered in ZRLOG 2.0.1.

An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.

NVD description · AI analysis pending
6.1<1% PoC
  • zrlog zrlog
CVE-2018-17420
+1 in the same advisory: …17421
An issue was discovered in ZrLog 2.0.3.

An issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords parameter.

NVD description · AI analysis pending
7.2
group max
1% PoC
  • zrlog zrlog