Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dogukanurker

First CVE: Jan 17, 2024Active for: 3 yearsTotal CVEs: 10
17.4
VTI Score
Low

Dogukanurker maintains a narrowly scoped portfolio centered on the Flask-based blogging application, which surfaces a cluster of web application security weaknesses spanning input validation, authorization control, and session management. The recurring vulnerability classes—including cross-site scripting, missing authorization, CSRF, and authorization-bypass conditions—reflect the authentication and access-control demands typical of web applications handling user-generated content and administrative functions. Defenders should treat this vendor's advisories in the context of the blogging platform's deployment footprint; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dogukanurker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2024
2 years ago
Most Recent CVE
Aug 19, 2025
343 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-28104CRITICAL
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
Apr 21, 20259.124NONO
CVE-2025-55736MEDIUM
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments
Aug 19, 20256.523NONO
CVE-2025-55737MEDIUM
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary c
Aug 19, 20256.522NONO
CVE-2025-55734MEDIUM
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes.
Aug 19, 20256.522NONO
CVE-2025-55735MEDIUM
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vul
Aug 19, 20255.419NONO
CVE-2025-53631MEDIUM
flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScri
Aug 14, 20255.419NONO
CVE-2025-28103MEDIUM
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
Apr 21, 20256.418NONO
CVE-2025-28102MEDIUM
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent paramet
Apr 21, 20256.118NONO
CVE-2025-28101MEDIUM
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a cra
Apr 17, 20256.518NONO
CVE-2024-22414MEDIUM
flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html t
Jan 17, 20245.417NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
90%
10%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None4 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dogukanurker.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dogukanurker — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dogukanurker's Products

View all 2 CNAs →

Top CWEs