CVE-2018-19556: Zblogcn Z-Blogphp

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

zb_system/admin/index.php?act=UploadMng in Z-BlogPHP 1.5 mishandles file preview, leading to content spoofing. NOTE: the software maintainer disputes that this is a vulnerability

Affected products

  • Zblogcn Z-Blogphp: version 1.5 only

Published 2018-11-26. Last modified 2026-06-17.