Dotnetblogengine's vulnerability footprint centers on BlogEngine.Net, a widely deployed open-source blogging platform built on the .NET framework, where exposure recurs through application-layer input-handling and data-exposure weakness classes including path traversal, XML external entity injection, cross-site scripting, and open redirect flaws. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility and appeal of this platform to both defenders and attackers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dotnetblogengine over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10717HIGH BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. | Jul 3, 2019 | 7.1 | 33 | NO | YES |
CVE-2019-10719HIGH BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/U | Jun 21, 2019 | 8.8 | 31 | NO | NO |
CVE-2019-10718HIGH BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | Jun 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11392HIGH BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | Jun 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-10721MEDIUM BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register. | Jul 3, 2019 | 6.1 | 21 | NO | NO |
CVE-2008-6476MEDIUM Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Mar 16, 2009 | 4.3 | 21 | NO | YES |
CVE-2013-6953MEDIUM BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. | Jan 3, 2014 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dotnetblogengine.
Media articles that mention a CVE ID that affects a product developed by Dotnetblogengine — matched by CVE ID, not by vendor name.