Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Appleple

First CVE: Jul 1, 2009Active for: 17 yearsTotal CVEs: 28
14.8
VTI Score
Low

Appleple is a Japanese content management system vendor with a focused product portfolio centered around the A-Blog CMS platform and associated web publishing tools. Despite the narrow product scope, the vendor occupies a meaningful position in the vulnerability landscape, particularly among organizations deploying Japanese-language and localized web content management infrastructure. Vulnerabilities affecting Appleple's products concentrate on web application input-handling weaknesses, including cross-site scripting, path traversal, server-side request forgery, and code injection flaws that are characteristic of CMS platforms handling user-supplied content and template processing. A meaningful share of these disclosures reach serious severity levels, reflecting the accessibility and privilege-escalation potential of these injection vectors in web publishing contexts. Defenders should treat Appleple CMS instances as requiring timely patching, particularly for internet-facing deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Appleple over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2009
17 years ago
Most Recent CVE
May 19, 2025
431 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-21142CRITICAL
Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to
Feb 24, 20229.829NONO
CVE-2025-41429CRITICAL
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's se
May 19, 20259.825NONO
CVE-2024-23348HIGH
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior
Jan 23, 20248.824NONO
CVE-2024-23180HIGH
Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior
Jan 23, 20248.824NONO
CVE-2025-36560HIGH
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive
May 19, 20257.522NONO
CVE-2025-29461HIGH
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.
Apr 17, 20257.622NONO
CVE-2025-31103HIGH
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This
Mar 31, 20257.522NONO
CVE-2024-23182HIGH
Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to
Jan 23, 20248.122NONO
CVE-2016-1178MEDIUM
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
Apr 12, 20176.522NONO
CVE-2022-24374MEDIUM
Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to V
Feb 24, 20226.121NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
68%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (96.4%)
Unknown1 (3.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (89.3%)
High2 (7.1%)
Unknown1 (3.6%)
User Interaction
None15 (53.6%)
Unknown1 (3.6%)
Required12 (42.9%)
Privileges Required
Low11 (39.3%)
High3 (10.7%)
None13 (46.4%)
Unknown1 (3.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Appleple.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Appleple — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Appleple's Products

View all 2 CNAs →

Top CWEs