CVE-2018-11208: Zblogcn Z-Blogphp

Medium severity, CVSS 4.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege

Affected products

  • Zblogcn Z-Blogphp: version 2.0.0 only

Published 2018-05-16. Last modified 2026-06-17.