Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
a-blog a-blog vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2022-25022
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows malicious users to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
Htmly Htmly 2.8.1
3.5
CVSSv2
CVE-2022-25020
A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the thumbnail path of a blog post.
Pluxml Pluxml 5.8.7
NA
CVE-2023-22856
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
Blogengine Blogengine.net 3.3.8.0
7.5
CVSSv2
CVE-2009-3337
SQL injection vulnerability in the Freetag (serendipity_event_freetag) plugin prior to 3.09 for Serendipity (S9Y) allows remote malicious users to execute arbitrary SQL commands via an unspecified parameter associated with Meta keywords in a blog entry.
S9y Serendipity Event Freetag
3.5
CVSSv2
CVE-2011-1504
Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x prior to 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.
Liferay Portal 5.2.1
Liferay Portal 5.1.0
Liferay Portal 5.1.2
Liferay Portal 6.0.4
Liferay Portal 6.0.5
Liferay Portal 5.1.1
Liferay Portal 6.0.0
Liferay Portal 6.0.2
Liferay Portal 6.0.1
Liferay Portal 5.2.2
Liferay Portal 5.2.3
Liferay Portal 5.2.0
Liferay Portal 5.0.0
Liferay Portal 5.0.1
Liferay Portal 6.0.3
4.3
CVSSv2
CVE-2021-46027
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added
Mysiteforme Project Mysiteforme -
4.3
CVSSv2
CVE-2018-16449
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.
Onethink Onethink 1.1.141212
4.3
CVSSv2
CVE-2014-9432
Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity prior to 2.0-rc2 allow remote malicious users to inject arbitrary web script or HTML via a blog comment in the QUERY_STRING to serendipity/index.php.
S9y Serendipity
NA
CVE-2023-33981
Briar prior to 1.4.22 allows malicious users to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimate message displayed alongside the spoofed one.
Briarproject Briar
NA
CVE-2022-37721
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
Pyrocms Pyrocms 3.9
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »