ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-27280
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

NVD description · AI analysis pending
7.8<1% PoC
  • mblog project mblog
CVE-2021-46028
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management.

In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.

NVD description · AI analysis pending
4.3<1% PoC
  • mblog project mblog
CVE-2020-19619
+3 in the same advisory: …19618 …19617 …19616
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

NVD description · AI analysis pending
5.4<1% PoC
  • mblog project mblog