Birdblog is a focused web-publishing platform where the observed vulnerability disclosures center on the core product and reflect input-handling issues characteristic of web applications, particularly cross-site scripting weaknesses in page-generation logic. Treat this as a narrow vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Birdblog over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6211MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter to (a) admin/admincore | Dec 1, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-5064MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comme | Sep 28, 2006 | 5.1 | 23 | NO | YES |
CVE-2014-5330MEDIUM Cross-site scripting (XSS) vulnerability in BirdBlog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Oct 19, 2014 | 4.3 | 19 | NO | NO |
CVE-2005-1592HIGH Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript. | May 16, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0882HIGH SQL injection vulnerability in admincore.php in BirdBlog before 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) userpw parameters. | May 2, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Birdblog.
Media articles that mention a CVE ID that affects a product developed by Birdblog — matched by CVE ID, not by vendor name.