CVE-2022-23810
- EPSS 0.3%
- Published 24.02.2022 15:15:28
- Last modified 21.11.2024 06:49:17
Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to V...
CVE-2022-21142
- EPSS 0.88%
- Published 24.02.2022 15:15:27
- Last modified 21.11.2024 06:43:58
Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allow...
CVE-2019-6034
- EPSS 0.42%
- Published 26.12.2019 16:15:12
- Last modified 21.11.2024 04:45:57
a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors.
CVE-2019-6033
- EPSS 0.4%
- Published 26.12.2019 16:15:12
- Last modified 21.11.2024 04:45:57
Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-1178
- EPSS 0.26%
- Published 12.04.2017 22:59:00
- Last modified 20.04.2025 01:37:25
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
CVE-2016-1179
- EPSS 0.28%
- Published 12.04.2017 22:59:00
- Last modified 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.