Mtons maintains a focused blogging platform product (MBlog) that, despite a narrow portfolio, sits prominently in the vulnerability landscape. The vendor's disclosures skew toward serious outcomes and concentrate across web-application input-handling and state-management weakness classes, including code injection, cross-site scripting, CSRF, and insufficient brute-force protections that are characteristic of web-facing content platforms. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mtons over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9004CRITICAL A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of e | Aug 15, 2025 | 9.1 | 28 | NO | NO |
CVE-2024-28713CRITICAL An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature. | Mar 28, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-9433MEDIUM A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation | Aug 26, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-9432MEDIUM A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation | Aug 26, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-8992MEDIUM A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack ma | Aug 15, 2025 | 6.5 | 22 | NO | NO |
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error messa | Aug 15, 2025 | 3.7 | 20 | NO | NO |
CVE-2025-9647MEDIUM A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cr | Aug 29, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-9431MEDIUM A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack | Aug 26, 2025 | 6.1 | 19 | NO | NO |
CVE-2025-9430MEDIUM A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input result | Aug 26, 2025 | 4.8 | 19 | NO | NO |
CVE-2025-9429MEDIUM A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulat | Aug 26, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mtons.
Media articles that mention a CVE ID that affects a product developed by Mtons — matched by CVE ID, not by vendor name.