Mblog Project maintains a focused blogging platform whose vulnerability profile centers on a single product, Mblog, which despite modest disclosure volume occupies a notable position within its application category. The observed vulnerability pattern recurs through application-layer weakness classes including cross-site scripting, cross-site request forgery, and unrestricted file uploads, reflecting the input-handling and file-processing demands inherent to web-based content management systems. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mblog Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27280HIGH OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | May 8, 2023 | 7.8 | 25 | NO | NO |
CVE-2020-19619MEDIUM Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. | Apr 1, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-19618MEDIUM Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. | Apr 1, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-19617MEDIUM Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. | Apr 1, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-46028MEDIUM In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the artic | Jan 20, 2022 | 4.3 | 18 | NO | NO |
CVE-2020-19616MEDIUM Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. | Apr 1, 2021 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mblog Project.
Media articles that mention a CVE ID that affects a product developed by Mblog Project — matched by CVE ID, not by vendor name.