Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zhenfeng13

First CVE: May 1, 2023Active for: 3 yearsTotal CVEs: 13
19.6
VTI Score
Low

Zhenfeng13 develops a portfolio of lightweight web-based applications focused on blogging and community platforms, including the widely deployed My-Blog and My-BBS products. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and centers persistently on web-tier deficiencies—cross-site scripting, improper access control, code injection, unsafe file uploads, and cross-site request forgery—that are characteristic of input-validation and privilege-boundary weaknesses in browser-facing applications. Defenders tracking this vendor should prioritize patches for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zhenfeng13 over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2023
3 years ago
Most Recent CVE
Aug 18, 2025
340 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-3593CRITICAL
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/
Apr 14, 20259.830NONO
CVE-2024-13144CRITICAL
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/contro
Jan 6, 20259.830NONO
CVE-2024-13145CRITICAL
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/co
Jan 6, 20259.829NONO
CVE-2025-3807CRITICAL
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/Uploa
Apr 19, 20259.827NONO
CVE-2025-8740MEDIUM
A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unknown function of the file /admin/categories/save of the compon
Aug 8, 20255.420NONO
CVE-2025-3808MEDIUM
A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery
Apr 19, 20256.520NONO
CVE-2023-29639MEDIUM
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the
May 1, 20235.419NONO
CVE-2023-29636MEDIUM
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to t
May 1, 20235.419NONO
CVE-2025-9101MEDIUM
A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipula
Aug 18, 20255.418NONO
CVE-2025-3591MEDIUM
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/bl
Apr 14, 20255.418NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None5 (38.5%)
Unknown0 (0.0%)
Required8 (61.5%)
Privileges Required
Low6 (46.2%)
High0 (0.0%)
None7 (53.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zhenfeng13.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zhenfeng13 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zhenfeng13's Products

View all 2 CNAs →

Top CWEs