Zhyd

Oneblog

13 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Published 16.09.2025 00:00:00
  • Last modified 23.09.2025 16:44:37

The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

Exploit
  • EPSS 0.05%
  • Published 27.03.2025 04:00:07
  • Last modified 01.04.2025 15:43:38

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side...

Exploit
  • EPSS 0.18%
  • Published 27.03.2025 04:00:05
  • Last modified 01.04.2025 15:43:23

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular exp...

Exploit
  • EPSS 0.22%
  • Published 10.02.2025 18:15:29
  • Last modified 28.03.2025 16:49:01

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

Exploit
  • EPSS 0.47%
  • Published 20.03.2024 21:15:32
  • Last modified 28.03.2025 16:45:49

A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module.

Exploit
  • EPSS 0.47%
  • Published 20.03.2024 21:15:32
  • Last modified 28.03.2025 16:48:37

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

Exploit
  • EPSS 0.09%
  • Published 20.03.2024 21:15:32
  • Last modified 21.11.2024 09:08:03

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

Exploit
  • EPSS 0.09%
  • Published 20.03.2024 21:15:32
  • Last modified 13.03.2025 18:15:39

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

Exploit
  • EPSS 0.41%
  • Published 20.03.2024 21:15:32
  • Last modified 01.04.2025 16:57:59

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.

Exploit
  • EPSS 0.75%
  • Published 20.03.2024 21:15:32
  • Last modified 28.03.2025 16:48:47

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.