Dogukanurker
Dogukanurker Flaskblog: vulnerabilidades y CVE
Dogukanurker Flaskblog tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-55737 | Media (6.9) | 0.29% | — | 19 ago 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post,… |
| CVE-2025-55736 | Crítica (9.3) | 0.27% | — | 19 ago 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the… |
| CVE-2025-55735 | Media (5.3) | 0.21% | — | 19 ago 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the… |
| CVE-2025-55734 | Media (6.9) | 0.37% | — | 19 ago 2025 | flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file… |
| CVE-2025-53631 | Media (5.3) | 0.22% | — | 14 ago 2025 | flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the… |
| CVE-2025-28104 | Crítica (9.1) | 0.40% | — | 21 abr 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. |
| CVE-2025-28103 | Media (6.4) | 0.22% | — | 21 abr 2025 | Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. |
| CVE-2025-28102 | Media (6.1) | 0.24% | — | 21 abr 2025 | A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost. |
| CVE-2025-28101 | Media (6.5) | 0.21% | — | 17 abr 2025 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. |
| CVE-2024-22414 | Media (5.4) | 0.41% | — | 17 ene 2024 | flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html template `user.html` contains the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.