Appleple

A-blog Cms

26 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Published 24.02.2022 15:15:28
  • Last modified 21.11.2024 06:49:17

Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to V...

  • EPSS 0.88%
  • Published 24.02.2022 15:15:27
  • Last modified 21.11.2024 06:43:58

Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allow...

  • EPSS 0.42%
  • Published 26.12.2019 16:15:12
  • Last modified 21.11.2024 04:45:57

a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.

  • EPSS 0.4%
  • Published 26.12.2019 16:15:12
  • Last modified 21.11.2024 04:45:57

Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.26%
  • Published 12.04.2017 22:59:00
  • Last modified 20.04.2025 01:37:25

The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.

  • EPSS 0.28%
  • Published 12.04.2017 22:59:00
  • Last modified 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.