Blogphp is a niche blogging platform whose vulnerability exposure centers on its eponymous application and recurs through application-layer weakness classes including cross-site scripting, SQL injection, improper input validation, and authentication bypasses. These patterns reflect the common risk surface of web-based content-management systems that accept and process user input across multiple trust boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blogphp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6745HIGH index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action. | Apr 23, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-0678MEDIUM SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action. | Feb 12, 2008 | 6.8 | 26 | NO | YES |
CVE-2008-6631MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter in a sendme | Apr 7, 2009 | 4.3 | 21 | NO | YES |
CVE-2008-0679MEDIUM Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Feb 12, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-2524MEDIUM BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie. | Jun 3, 2008 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blogphp.
Media articles that mention a CVE ID that affects a product developed by Blogphp — matched by CVE ID, not by vendor name.