Myblog maintains a narrowly scoped blogging platform whose vulnerabilities reflect the characteristic challenges of web application development, spanning path traversal, cross-site scripting, SQL injection, and related input-handling weaknesses. The vendor's disclosures frequently acquire public exploit code, making timely patching essential for deployments exposed to the internet. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myblog over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1540MEDIUM Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the ta | Apr 26, 2010 | 5.0 | 36 | NO | YES |
CVE-2007-2081HIGH MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php. | Apr 18, 2007 | 7.5 | 31 | NO | YES |
CVE-2008-4341HIGH add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin. | Sep 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-2963MEDIUM Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to ( | Jul 2, 2008 | 6.8 | 26 | NO | YES |
CVE-2008-6193MEDIUM Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | Feb 19, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-2962MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and | Jul 2, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-2082MEDIUM Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content pa | Apr 18, 2007 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myblog.
Media articles that mention a CVE ID that affects a product developed by Myblog — matched by CVE ID, not by vendor name.