Blog Cms maintains a focused content-management platform whose vulnerabilities center on web-application input handling, with the recurring weakness classes of code injection, cross-site scripting, and SQL injection reflecting common risks in dynamically generated web content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blog Cms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4750MEDIUM Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administr | Mar 1, 2011 | 6.8 | 29 | NO | YES |
CVE-2008-0360HIGH Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter | Jan 18, 2008 | 7.5 | 28 | NO | YES |
CVE-2010-4749MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parame | Mar 1, 2011 | 4.3 | 23 | NO | YES |
CVE-2018-16779MEDIUM BlogCMS through 2016-10-25 has XSS via a comment. | Sep 10, 2018 | 6.1 | 21 | NO | NO |
CVE-2008-0359MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index | Jan 18, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-0450HIGH Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index. | Jan 25, 2008 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blog Cms.
Media articles that mention a CVE ID that affects a product developed by Blog Cms — matched by CVE ID, not by vendor name.