ZeroHour

Vulnerabilities

53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-13814
+3 in the same advisory: …13813 …13816 …13815
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2.

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.5
group max
<1% PoC ×2
  • mogublog project mogublog
CVE-2025-3005
+1 in the same advisory: …3004
A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic.

A vulnerability was found in Sayski ForestBlog up to 20250321 and classified as problematic. Affected by this issue is some unknown functionality of the component Friend Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1% PoC ×2
  • forestblog project forestblog
CVE-2024-57498
Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.

NVD description · AI analysis pending
4.8<1% PoC
  • forestblog project forestblog
CVE-2024-37271
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affe

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from n/a through <= 3.27.0.

NVD description · AI analysis pending
4.8<1%
  • print my blog project print my blog
CVE-2024-39313
toy-blog is a headless content management system implementation.

toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, articles with private visibility can be read if the reader does not set credentials for the request. Users should upgrade to 0.6.1 or later to receive a patch. No known workarounds are available.

NVD description · AI analysis pending
5.3<1%
  • toy-blog project toy-blog
CVE-2023-6887
A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630.

A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248247.

NVD description · AI analysis pending
9.8<1% PoC
  • forestblog project forestblog
CVE-2023-2435
+1 in the same advisory: …2436
The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute.

The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

NVD description · AI analysis pending
7.2
group max
1%
  • blog-in-blog project blog-in-blog
CVE-2023-2954
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.

Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.

NVD description · AI analysis pending
5.4<1% PoC
  • djangoblog project djangoblog
CVE-2021-27280
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

NVD description · AI analysis pending
7.8<1% PoC
  • mblog project mblog
CVE-2023-2101
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2.

A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226109 was assigned to this vulnerability.

NVD description · AI analysis pending
6.5<1% PoC ×2
  • mogublog project mogublog
CVE-2023-1937
A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog.

A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.

NVD description · AI analysis pending
4.3<1% PoC
  • my-blog project my-blog
CVE-2023-27847
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass

SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

NVD description · AI analysis pending
9.85% PoC
  • xipblog project xipblog
CVE-2023-27093
Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.

Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.

NVD description · AI analysis pending
6.1<1% PoC
  • my-blog project my-blog
CVE-2022-40037
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.

An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.

NVD description · AI analysis pending
9.82% PoC
  • javaweb blog project javaweb blog
CVE-2022-40034
Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.

Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • javaweb blog project javaweb blog
CVE-2022-4400
A vulnerability was found in zbl1996 FS-Blog and classified as problematic.

A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing of the component Title Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-215267.

NVD description · AI analysis pending
6.1<1%
  • fs-blog project fs-blog
CVE-2022-30517
Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).

Mogu blog 5.2 is vulnerable to Cross Site Scripting (XSS).

NVD description · AI analysis pending
6.1<1% PoC
  • mogublog project mogublog
CVE-2022-1787
The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin ch

The Sideblog WordPress plugin through 6.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping

NVD description · AI analysis pending
5.4<1% PoC
  • sideblog project sideblog
CVE-2022-27174
Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentic

Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the administrator and delete a blog article or a category via a specially crafted page.

NVD description · AI analysis pending
4.3<1%
  • easy blog project easy blog
CVE-2022-29659
Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

NVD description · AI analysis pending
9.82% PoC
  • responsive online blog project responsive online blog
CVE-2021-42233
The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability.

The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any user opens a particular blog hosted on an attackers' site, XSS may occur.

NVD description · AI analysis pending
5.4<1% PoC ×3
  • simple blog project simple blog
CVE-2022-28512
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 .

A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

NVD description · AI analysis pending
9.81% PoC
  • fantastic blog project fantastic blog
CVE-2022-29020
ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.

ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.

NVD description · AI analysis pending
6.1<1% PoC
  • forestblog project forestblog
CVE-2022-23626
m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog.

m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

NVD description · AI analysis pending
8.810% PoC
  • blog project blog
CVE-2021-46085
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions.

OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.

NVD description · AI analysis pending
6.5<1% PoC
  • oneblog project oneblog
CVE-2021-46033
+1 in the same advisory: …46034
In ForestBlog, as of 2021-12-28, File upload can bypass verification.

In ForestBlog, as of 2021-12-28, File upload can bypass verification.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • forestblog project forestblog
CVE-2021-46028
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management.

In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.

NVD description · AI analysis pending
4.3<1% PoC
  • mblog project mblog
CVE-2021-46025
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8.

A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.

NVD description · AI analysis pending
5.4<1% PoC
  • oneblog project oneblog
CVE-2021-43682
thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php.

thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST'].

NVD description · AI analysis pending
6.1<1% PoC
  • thinkphp-bjyblog project thinkphp-bjyblog
CVE-2021-24636
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Pri

The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link

NVD description · AI analysis pending
8.1<1% PoC
  • print my blog project print my blog
CVE-2021-24479
The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticat

The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issue

NVD description · AI analysis pending
4.8<1% PoC
  • drawblog project drawblog
CVE-2021-26224
Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the searc

Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

NVD description · AI analysis pending
6.1<1% PoC
  • fantastic blog project fantastic blog
CVE-2020-18964
Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain priv

Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.

NVD description · AI analysis pending
8.8<1% PoC
  • forestblog project forestblog
CVE-2020-19619
+3 in the same advisory: …19618 …19617 …19616
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

NVD description · AI analysis pending
5.4<1% PoC
  • mblog project mblog
CVE-2020-21180
+1 in the same advisory: …21179
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.

Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.

NVD description · AI analysis pending
9.81% PoC
  • koa2-blog project koa2-blog
CVE-2019-17494
laravel-bjyblog 6.1.1 has XSS via a crafted URL.

laravel-bjyblog 6.1.1 has XSS via a crafted URL.

NVD description · AI analysis pending
6.1<1% PoC
  • laravel-bjyblog project laravel-bjyblog
CVE-2019-9842
madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data:

madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in app_code/handlers/PostHandler.cs writes a decoded base64 string to a file without validating the extension.

NVD description · AI analysis pending
7.22% PoC
  • miniblog project miniblog
CVE-2019-11565
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.

Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.

NVD description · AI analysis pending
9.83% PoC
  • print my blog project print my blog
CVE-2019-3494
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.

Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.

NVD description · AI analysis pending
7.51% PoC
  • simply-blog project simply-blog
CVE-2018-16780
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.

Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.

NVD description · AI analysis pending
5.4<1% PoC
  • complete responsive cms blog project complete responsive cms blog