HIGH

CVE-2026-52521

2026-08-03 CVSS v3.1
CVSS
8.1

Description

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

0.23%
Probability of exploitation in next 30 days
14.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE