Sblog is a web-based blogging platform whose vulnerability profile centers on application-layer weaknesses in web-request handling and content rendering, particularly cross-site request forgery, cross-site scripting, and input-validation issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sblog over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1801HIGH Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the conf_lang_defau | Apr 2, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-1135MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) | Mar 10, 2006 | 4.3 | 23 | NO | YES |
CVE-2007-5818HIGH Cross-site request forgery (CSRF) vulnerability in blocks_edit_do.php in sBlog 0.7.3 Beta allows remote attackers to change arbitrary blocks as administrators. | Nov 5, 2007 | 7.6 | 19 | NO | NO |
CVE-2006-0101MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) key | Jan 6, 2006 | 4.3 | 16 | NO | NO |
CVE-2007-4102MEDIUM Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/></> sequence in the se | Jul 31, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sblog.
Media articles that mention a CVE ID that affects a product developed by Sblog — matched by CVE ID, not by vendor name.