A Blogcms
Vendor:
First CVE: Apr 12, 2017 · Active for 9 years
27
Total CVEs
Bottom 1%
5.4
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact A Blogcms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2017
9 years ago
Most Recent CVE
May 19, 2025
435 days ago
CVE Severity & Scoring
A Blogcms27 CVEs
67%
26%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low25 (92.6%)
High2 (7.4%)
Unknown0 (0.0%)
User Interaction
None15 (55.6%)
Unknown0 (0.0%)
Required12 (44.4%)
Privileges Required
Low11 (40.7%)
High3 (11.1%)
None13 (48.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21142CRITICAL Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to | Feb 24, 2022 | 9.8 | 29 | NO | NO |
CVE-2025-41429CRITICAL a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's se | May 19, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-23348HIGH Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior | Jan 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-23180HIGH Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior | Jan 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-36560HIGH Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive | May 19, 2025 | 7.5 | 22 | NO | NO |
CVE-2025-29461HIGH An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path. | Apr 17, 2025 | 7.6 | 22 | NO | NO |
CVE-2025-31103HIGH Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This | Mar 31, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-23182HIGH Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to | Jan 23, 2024 | 8.1 | 22 | NO | NO |
CVE-2016-1178MEDIUM The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors. | Apr 12, 2017 | 6.5 | 22 | NO | NO |
CVE-2022-24374MEDIUM Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to V | Feb 24, 2022 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For A Blogcms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.15 | 1 | 7.6 | 0.4% | 0 | 0 |
| 3.0.0 | 3 | 6.2 | 0.9% | 0 | 0 |