Mblog Project
Mblog Project Mblog: vulnerabilidades y CVE
Mblog Project Mblog tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-27280 | Alta (7.8) | 0.97% | — | 8 may 2023 | OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. |
| CVE-2021-46028 | Media (4.3) | 0.36% | — | 20 ene 2022 | In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted. |
| CVE-2020-19619 | Media (5.4) | 0.64% | — | 1 abr 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. |
| CVE-2020-19618 | Media (5.4) | 0.64% | — | 1 abr 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. |
| CVE-2020-19617 | Media (5.4) | 0.60% | — | 1 abr 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. |
| CVE-2020-19616 | Media (5.4) | 0.60% | — | 1 abr 2021 | Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. |