Wheatblog is a narrowly scoped blogging platform whose vulnerability disclosures cluster around a single product line. The vendor's vulnerabilities acquire public exploit tooling with meaningful frequency, reflecting the appeal of web-facing content-management systems as targets for defacement and unauthorized access. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wheatblog over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4198MEDIUM PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PH | Aug 17, 2006 | 5.1 | 24 | NO | YES |
CVE-2007-3557MEDIUM SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login par | Jul 4, 2007 | 6.8 | 20 | NO | NO |
CVE-2006-5195MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0 and 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the prove | Oct 10, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-5921MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, an | Nov 15, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-5922MEDIUM index.php in Wheatblog (wB) allows remote attackers to obtain sensitive information via certain values of the postPtr[] and next parameters, which reveals the path in an error mess | Nov 15, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-7002MEDIUM Cross-site scripting (XSS) vulnerability in add_comment.php in Wheatblog (wB) 1.1 allows remote attackers to inject arbitrary web script or HTML via the Email field. NOTE: the pro | Feb 12, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wheatblog.
Media articles that mention a CVE ID that affects a product developed by Wheatblog — matched by CVE ID, not by vendor name.