Dogukanurker maintains a narrowly scoped portfolio centered on the Flask-based blogging application, which surfaces a cluster of web application security weaknesses spanning input validation, authorization control, and session management. The recurring vulnerability classes—including cross-site scripting, missing authorization, CSRF, and authorization-bypass conditions—reflect the authentication and access-control demands typical of web applications handling user-generated content and administrative functions. Defenders should treat this vendor's advisories in the context of the blogging platform's deployment footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dogukanurker over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-28104CRITICAL Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. | Apr 21, 2025 | 9.1 | 24 | NO | NO |
CVE-2025-55736MEDIUM flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments | Aug 19, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-55737MEDIUM flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary c | Aug 19, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-55734MEDIUM flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. | Aug 19, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-55735MEDIUM flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vul | Aug 19, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-53631MEDIUM flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScri | Aug 14, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-28103MEDIUM Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. | Apr 21, 2025 | 6.4 | 18 | NO | NO |
CVE-2025-28102MEDIUM A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent paramet | Apr 21, 2025 | 6.1 | 18 | NO | NO |
CVE-2025-28101MEDIUM An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a cra | Apr 17, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-22414MEDIUM flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html t | Jan 17, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dogukanurker.
Media articles that mention a CVE ID that affects a product developed by Dogukanurker — matched by CVE ID, not by vendor name.