Will Kraft develops the EZ-Blog platform, a web-based blogging application with a focused but above-typical presence in the vulnerability landscape. The recurring issues cluster around foundational web-application weaknesses: SQL injection in database interactions and improper authentication mechanisms, which are characteristic flaws in custom web platforms. Current severity, exploitation, and exposure details are shown in the live statistics alongside this summary.
The number and severity of CVEs published that impact products developed by Will Kraft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4801HIGH EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts. | Apr 23, 2010 | 7.5 | 34 | NO | YES |
CVE-2009-1626HIGH SQL injection vulnerability in public/specific.php in EZ-Blog before Beta 2 20090427, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands v | May 12, 2009 | 7.5 | 28 | NO | YES |
CVE-2009-4805MEDIUM Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter | Apr 23, 2010 | 6.8 | 26 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Will Kraft.
Media articles that mention a CVE ID that affects a product developed by Will Kraft — matched by CVE ID, not by vendor name.