Blog Project maintains a narrowly scoped blogging platform whose vulnerability footprint centers on application-layer input handling and data-validation issues, including SQL injection, improper input validation, unrestricted file uploads, and unchecked return values. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blog Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23626HIGH m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings | Feb 8, 2022 | 8.8 | 44 | NO | YES |
CVE-2017-14345CRITICAL SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php. | Sep 12, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-14346CRITICAL upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for | Sep 12, 2017 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blog Project.
Media articles that mention a CVE ID that affects a product developed by Blog Project — matched by CVE ID, not by vendor name.