Products: 1
    Vulnerabilities: 10
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-53888

    Zomplog 3.9 Remote Code Execution via Authenticated File Manipulation

    Last Modified: May 25, 2026
    Published: Dec 15, 2025

    CVE-2023-53887

    Zomplog 3.9 Cross-Site Scripting Vulnerability via Page Creation

    Last Modified: Apr 07, 2026
    Published: Dec 15, 2025

    CVE-2007-5278

    Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable.

    Last Modified: Apr 23, 2026
    Published: Oct 08, 2007

    CVE-2007-5231

    Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticated administrators to upload and execute arbitrary .php files by sending a modified MIME type. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2007-5230.

    Last Modified: Apr 23, 2026
    Published: Oct 05, 2007

    CVE-2007-5230

    admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administrative actions via a direct request. NOTE: this can be leveraged for code execution by exploiting CVE-2007-5231.

    Last Modified: Apr 23, 2026
    Published: Oct 05, 2007
    Items Per Page
    Zomplog Vulnerabilities & Security CVEs | CVE-DB