CVE-2018-7736: Zblogcn Z-Blogphp

Medium severity, CVSS 6.1. EPSS: 3.3% chance of exploitation in the next 30 days.

In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability

Affected products

  • Zblogcn Z-Blogphp: version 1.5.1.1740 only

Published 2018-03-06. Last modified 2026-06-17.