ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-9647
A weakness has been identified in mtons mblog up to 3.5.0.

A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

NVD description · AI analysis pending
2.1<1% PoC
  • mtons mblog
CVE-2025-9433
+4 in the same advisory: …9432 …9431 …9429 …9430
A vulnerability was found in mtons mblog up to 3.5.0.

A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.

NVD description · AI analysis pending
2.1
group max
<1% PoC
  • mtons mblog
CVE-2025-9407
A flaw has been found in mtons mblog up to 3.5.0.

A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.

NVD description · AI analysis pending
2.0<1% PoC
  • mtons mblog
CVE-2025-9004
+2 in the same advisory: …9005 …8992
A vulnerability was found in mtons mblog up to 3.5.0.

A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.9
group max
<1% PoC
  • mtons mblog
CVE-2025-8927
A vulnerability was determined in mtons mblog up to 3.5.0.

A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.9<1% PoC
  • mtons mblog
CVE-2024-13198
+1 in the same advisory: …13199
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0.

A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.3
group max
<1% PoC
  • mtons mblog
CVE-2024-28713
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

NVD description · AI analysis pending
9.81% PoC ×7
  • mtons mblog