Known vulnerabilities in a-blog cms

Software: a-blog cms
Software CPE: cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
Total vulnerabilities: 23
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting a-blog cms a-blog cms is affected by 23 known vulnerabilities: 2 high, 6 medium, 15 low Critical High Medium Low

Vulnerabilities (23)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU149504 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-87727
CWE-22 Medium
No
No
3.2.34 14.09.2026 SB2026091431
#VU109451 - Improper Output Neutralization for Logs
CVE-2025-41429
CWE-117 Low
No
No
2.8.86, 2.9.53, 2.10.64, 2.11.76, 3.0.48, 3.1.44 20.05.2025 SB2025052013
#VU109449 - Server-Side Request Forgery (SSRF)
CVE-2025-36560
CWE-918 High
No
No
2.8.86, 2.9.53, 2.10.64, 2.11.76, 3.0.48, 3.1.44 20.05.2025 SB2025052013
#VU109448 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-32999
CWE-79 Low
No
No
3.0.47, 3.1.43 20.05.2025 SB2025052013
#VU109445 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-27566
CWE-22 Low
No
No
3.0.47, 3.1.43 20.05.2025 SB2025052013
#VU106235 - Deserialization of Untrusted Data
CVE-2025-31103
CWE-502 High
No
No
2.8.80, 2.9.46, 2.10.58, 2.11.70, 3.0.41, 3.1.37 28.03.2025 SB2025032815
#VU88471 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-31396
CWE-94 Low
No
No
3.0.32, 3.1.12 11.04.2024 SB2024041138
#VU88470 - Server-Side Request Forgery (SSRF)
CVE-2024-30420
CWE-918 Low
No
No
3.0.32, 3.1.12 11.04.2024 SB2024041138
#VU88469 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-31395
CWE-79 Low
No
No
2.10.53, 2.11.61, 3.0.32, 3.1.12 11.04.2024 SB2024041138
#VU88468 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-31394
CWE-22 Medium
No
No
2.10.53, 2.11.61, 3.0.32, 3.1.12 11.04.2024 SB2024041138
#VU88467 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-30419
CWE-79 Low
No
No
2.10.53, 2.11.61, 3.0.32, 3.1.12 11.04.2024 SB2024041138
#VU87310 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-27279
CWE-22 Medium
No
No
2.10.52, 2.11.60, 3.0.31, 3.1.10 08.03.2024 SB2024030840
#VU85632 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-23182
CWE-22 Medium
No
No
2.10.50, 2.11.58, 3.0.29, 3.1.7 22.01.2024 SB2024012208
#VU85631 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-23348
CWE-79 Low
No
No
2.10.50, 2.11.58, 3.0.29, 3.1.7 22.01.2024 SB2024012208
#VU85630 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-23183
CWE-79 Low
No
No
2.10.50, 2.11.58, 3.0.29, 3.1.7 22.01.2024 SB2024012208
#VU85629 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-23181
CWE-79 Low
No
No
2.10.50, 2.11.58, 3.0.29, 3.1.7 22.01.2024 SB2024012208
#VU85628 - Improper input validation
CVE-2024-23180
CWE-20 Medium
No
No
2.10.50, 2.11.58, 3.0.29, 3.1.7 22.01.2024 SB2024012208
#VU60703 - Improper Authentication
CVE-2022-21142
CWE-287 Medium
No
No
2.8.74, 2.9.39, 2.10.43, 2.11.41 18.02.2022 SB2022021802
#VU60702 - Exposure of sensitive information to an unauthorized actor
CVE-2022-23810
CWE-200 Low
No
No
2.8.75, 2.9.40, 2.10.44, 2.11.42, 3.0.1 18.02.2022 SB2022021801
#VU60701 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-23916
CWE-79 Low
No
No
2.8.75, 2.9.40, 2.10.44, 2.11.42, 3.0.1 18.02.2022 SB2022021801


Showing elements 1 - 20 out of 23