Products: 1
    Vulnerabilities: 12
    Known Exploited: 0
    3
    Critical Level Threats
    2
    High Level Threats
    7
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-45872

    zrlog v3.1.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the downloadUrl parameter.

    Last Modified: Aug 14, 2025
    Published: Jul 01, 2025

    CVE-2020-27514

    Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

    Last Modified: Nov 21, 2024
    Published: Aug 11, 2023

    CVE-2020-21052

    Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.

    Last Modified: Dec 10, 2024
    Published: Jun 20, 2023

    CVE-2021-44094

    ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

    Last Modified: Nov 21, 2024
    Published: Nov 28, 2021

    CVE-2021-44093

    A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass the original limit, upload the JSP file to get a WebShell

    Last Modified: Nov 21, 2024
    Published: Nov 28, 2021
    Items Per Page