Skip to main content

Vendor/product archive

appleple / a-blog_cms CVEs

Beta · best-effort

26 CVEs tagged to appleple / a-blog_cms2 Critical, 4 High, 19 Medium, 1 Low, 0 Unrated.

CVE-2025-41429

Published May 19, 2025

a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's s…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-36560

Published May 19, 2025

Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitiv…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-32999

Published May 19, 2025

Cross-site scripting vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and prior to Ver. 3.0.47. This issue exists in a specific field in the entry editing screen,…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27566

Published May 19, 2025

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-31103

Published Mar 31, 2025

Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. Thi…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-31396

Published May 22, 2024

Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploit…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31395

Published May 22, 2024

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions pr…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31394

Published May 22, 2024

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions pri…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30420

Published May 22, 2024

Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vuln…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30419

Published May 22, 2024

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series versions prior to Ver.3.0.32, Ver.2.11.x series versions pr…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27279

Published Mar 12, 2024

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25559

Published Feb 15, 2024

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23782

Published Jan 28, 2024

Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions pri…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23348

Published Jan 23, 2024

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23183

Published Jan 23, 2024

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to V…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23182

Published Jan 23, 2024

Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23181

Published Jan 23, 2024

Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to V…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23180

Published Jan 23, 2024

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24374

Published Feb 24, 2022

Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23916

Published Feb 24, 2022

Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23810

Published Feb 24, 2022

Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x ser…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21142

Published Feb 24, 2022

Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-6034

Published Dec 26, 2019

a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6033

Published Dec 26, 2019

Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1179

Published Apr 12, 2017

Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2