Appleple is a Japanese content management system vendor with a focused product portfolio centered around the A-Blog CMS platform and associated web publishing tools. Despite the narrow product scope, the vendor occupies a meaningful position in the vulnerability landscape, particularly among organizations deploying Japanese-language and localized web content management infrastructure. Vulnerabilities affecting Appleple's products concentrate on web application input-handling weaknesses, including cross-site scripting, path traversal, server-side request forgery, and code injection flaws that are characteristic of CMS platforms handling user-supplied content and template processing. A meaningful share of these disclosures reach serious severity levels, reflecting the accessibility and privilege-escalation potential of these injection vectors in web publishing contexts. Defenders should treat Appleple CMS instances as requiring timely patching, particularly for internet-facing deployments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appleple over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21142CRITICAL Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to | Feb 24, 2022 | 9.8 | 29 | NO | NO |
CVE-2025-41429CRITICAL a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's se | May 19, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-23348HIGH Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior | Jan 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-23180HIGH Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior | Jan 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-36560HIGH Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive | May 19, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-29461HIGH An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path. | Apr 17, 2025 | 7.6 | 22 | NO | NO |
CVE-2025-31103HIGH Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This | Mar 31, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-23182HIGH Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to | Jan 23, 2024 | 8.1 | 22 | NO | NO |
CVE-2016-1178MEDIUM The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors. | Apr 12, 2017 | 6.5 | 22 | NO | NO |
CVE-2022-24374MEDIUM Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to V | Feb 24, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appleple.
Media articles that mention a CVE ID that affects a product developed by Appleple — matched by CVE ID, not by vendor name.