CVE-2018-11209: Zblogcn Z-Blogphp

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor declined to accept this as a valid issue

Affected products

  • Zblogcn Z-Blogphp: version 2.0.0 only

Published 2018-05-16. Last modified 2026-06-17.