Wikyblog is a modestly represented web publishing platform whose vulnerability footprint centers on a single product and reflects common application-layer weaknesses including cross-site scripting, improper authentication, and code-injection flaws endemic to dynamic content generation. The vendor's disclosures show a marked tendency toward public exploit availability, making timely patching essential for deployments exposed to untrusted networks. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikyblog over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0757MEDIUM Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable e | Feb 27, 2010 | 6.5 | 28 | NO | YES |
CVE-2010-0755HIGH PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in the langFile parameter. | Feb 27, 2010 | 7.5 | 28 | NO | YES |
CVE-2006-5193HIGH PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir pa | Oct 10, 2006 | 7.5 | 28 | NO | YES |
CVE-2010-0756MEDIUM Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php | Feb 27, 2010 | 5.8 | 26 | NO | YES |
CVE-2008-6097MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Sp | Feb 9, 2009 | 4.3 | 24 | NO | YES |
CVE-2010-0754MEDIUM Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitrary web script or HTML via the | Feb 27, 2010 | 4.3 | 21 | NO | YES |
CVE-2007-2781MEDIUM Cross-site scripting (XSS) vulnerability in include/sessionRegister.php in WikyBlog before 1.4.13 allows remote attackers to inject arbitrary web script or HTML, probably via vecto | May 21, 2007 | 6.8 | 18 | NO | NO |
CVE-2006-6465MEDIUM Directory traversal vulnerability in WBmap.php in WikyBlog 1.3.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences | Dec 11, 2006 | 6.5 | 18 | NO | NO |
CVE-2006-6466MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WBmap.php in WikyBlog 1.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) key, (2) d, | Dec 11, 2006 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikyblog.
Media articles that mention a CVE ID that affects a product developed by Wikyblog — matched by CVE ID, not by vendor name.