PT-2026-33780 · Z Blogphp · Z-Blogphp

Qingyunsec

·

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-6650

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Z-BlogPHP version 1.7.5
Description An issue in the ZBA File Handler component allows for unrestricted file upload. This occurs within the App::UnPack() function located in the '/zb users/plugin/AppCentre/app upload.php' file and can be triggered remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the '/zb users/plugin/AppCentre/app upload.php' file or disabling the App::UnPack() function.

Exploit

Unrestricted File Upload

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-6650

Affected Products

Z-Blogphp