Easy Blog Project maintains a narrowly scoped blogging platform whose vulnerability profile centers on cross-site request forgery weaknesses in the Easy Blog product itself. This reflects the web-application context of the software and the authentication and session-handling demands of user-driven content management. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easy Blog Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27174MEDIUM Cross-site request forgery (CSRF) vulnerability in Easy Blog for EC-CUBE4 Ver.1.0.1 and earlier allows a remote unauthenticated attacker to hijack the authentication of the adminis | Jun 13, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Blog Project.
Media articles that mention a CVE ID that affects a product developed by Easy Blog Project — matched by CVE ID, not by vendor name.