Alma maintains a focused blogging platform product, with the durable signal centered on web-application input-handling and access-control issues such as cross-site scripting, improper access control, and observable response discrepancies. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alma over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1146MEDIUM Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript paylo | Mar 19, 2024 | 6.1 | 20 | NO | NO |
CVE-2024-1144MEDIUM Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the applicat | Mar 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-1145MEDIUM User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered | Mar 19, 2024 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alma.
Media articles that mention a CVE ID that affects a product developed by Alma — matched by CVE ID, not by vendor name.