Blogifier is a niche blogging platform whose vulnerability profile centers on web-application input-handling and path-traversal weaknesses, including cross-site scripting and path-traversal flaws that are characteristic of direct file-access patterns in content-management systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blogifier over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12277CRITICAL Blogifier 2.3 before 2019-05-11 does not properly restrict APIs, as demonstrated by missing checks for .. in a pathname. | May 22, 2019 | 9.8 | 29 | NO | NO |
CVE-2022-35569MEDIUM Blogifier v3.0 was discovered to contain an arbitrary file upload vulnerability at /api/storage/upload/PostImage. This vulnerability allows attackers to execute arbitrary web scrip | Jul 20, 2022 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blogifier.
Media articles that mention a CVE ID that affects a product developed by Blogifier — matched by CVE ID, not by vendor name.