Zrlog · Zrlog · CVE-2025-9591
**Name of the Vulnerable Software and Affected Versions**
ZrLog versions up to 3.1.5
**Description**
A security vulnerability exists in ZrLog, potentially allowing for cross site scripting. The vulnerability affects unknown code within the `/api/admin/template/config` file of the Theme Configuration Form component. Manipulation of the `footerLink` argument can trigger the issue. The exploit has been publicly disclosed.
**Recommendations**
Versions prior to 3.1.5 should be updated.