HIGH
CVE-2026-52521
CVSS
8.1
Description
A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
0.23%
Probability of exploitation in next 30 days
14.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.