Zhenfeng13 develops a portfolio of lightweight web-based applications focused on blogging and community platforms, including the widely deployed My-Blog and My-BBS products. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and centers persistently on web-tier deficiencies—cross-site scripting, improper access control, code injection, unsafe file uploads, and cross-site request forgery—that are characteristic of input-validation and privilege-boundary weaknesses in browser-facing applications. Defenders tracking this vendor should prioritize patches for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zhenfeng13 over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3593CRITICAL A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/ | Apr 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-13144CRITICAL A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/contro | Jan 6, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-13145CRITICAL A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/co | Jan 6, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-3807CRITICAL A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/Uploa | Apr 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-8740MEDIUM A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unknown function of the file /admin/categories/save of the compon | Aug 8, 2025 | 5.4 | 20 | NO | NO |
CVE-2025-3808MEDIUM A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery | Apr 19, 2025 | 6.5 | 20 | NO | NO |
CVE-2023-29639MEDIUM Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the | May 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-29636MEDIUM Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to t | May 1, 2023 | 5.4 | 19 | NO | NO |
CVE-2025-9101MEDIUM A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipula | Aug 18, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-3591MEDIUM A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/bl | Apr 14, 2025 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zhenfeng13.
Media articles that mention a CVE ID that affects a product developed by Zhenfeng13 — matched by CVE ID, not by vendor name.