« Volver al listado

Blogengine

Blogengine.net: vulnerabilidades y CVE

Blogengine.net tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses0
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-33404Crítica (9.8)26%—26 jun 2023
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
CVE-2023-33405Media (6.1)31%—21 jun 2023
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
CVE-2023-22858Media (5.3)0.43%—6 mar 2023
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
CVE-2023-22857Media (5.4)0.36%—6 mar 2023
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog…
CVE-2023-22856Media (5.4)0.38%—6 mar 2023
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
CVE-2022-41417Crítica (9.8)0.76%—18 ene 2023
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
CVE-2022-41418Alta (7.2)1.2%—19 dic 2022
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
CVE-2022-36600Media (4.8)0.55%—2 sept 2022
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted…
CVE-2022-28921Media (6.5)0.73%—18 may 2022
A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.
CVE-2022-25591Crítica (9.1)2.7%—13 may 2022
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
CVE-2019-10720Alta (8.8)7.1%—21 jun 2019
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.
CVE-2018-14485Crítica (9.8)16%—7 may 2019
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
CVE-2019-6714Crítica (9.8)32%—21 mar 2019
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially…

Otros productos de Blogengine