ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-60355
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

NVD description · AI analysis pending
9.8<1% PoC
  • zhyd oneblog
CVE-2025-56264
The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

NVD description · AI analysis pending
7.5<1% PoC
  • zhyd oneblog
CVE-2025-2833
+1 in the same advisory: …2835
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9.

A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9
group max
<1% PoC ×2
  • zhyd oneblog
CVE-2024-54954
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

NVD description · AI analysis pending
8.0<1% PoC
  • zhyd oneblog
CVE-2024-29470
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • zhyd oneblog
CVE-2022-34012
+2 in the same advisory: …34013 …34011
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • zhyd oneblog