Filtered by vendor Mblog Project
Subscriptions
Total
9 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-9005 | 1 Mblog Project | 1 Mblog | 2025-08-16 | 3.7 Low |
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. | ||||
CVE-2025-8992 | 1 Mblog Project | 1 Mblog | 2025-08-16 | 4.3 Medium |
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2025-9004 | 1 Mblog Project | 1 Mblog | 2025-08-16 | 3.7 Low |
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. | ||||
CVE-2021-27280 | 1 Mblog Project | 1 Mblog | 2025-01-29 | 7.8 High |
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | ||||
CVE-2021-46028 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 4.3 Medium |
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted. | ||||
CVE-2020-19619 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. | ||||
CVE-2020-19618 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. | ||||
CVE-2020-19617 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. | ||||
CVE-2020-19616 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. |
Page 1 of 1.