Zhyd maintains the OneBlob blogging platform, a modestly represented product in the landscape that exposes a focused but recurring set of web-application vulnerabilities. The vendor's disclosures center on input-handling and template-processing weaknesses—including cross-site scripting, server-side request forgery, template injection, and resource-consumption flaws—that are characteristic of content-management and publishing systems where user input flows through rendering pipelines. Defenders deploying this platform should prioritize input validation and access-control review; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zhyd over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60355CRITICAL zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | Oct 28, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-56264HIGH The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. | Sep 16, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-54954HIGH OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department. | Feb 10, 2025 | 8.0 | 22 | NO | NO |
CVE-2024-29473MEDIUM OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module. | Mar 20, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-29470MEDIUM OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links. | Mar 20, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-29471MEDIUM OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module. | Mar 20, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-29469MEDIUM A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List | Mar 20, 2024 | 6.1 | 18 | NO | NO |
CVE-2025-2833MEDIUM A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipul | Mar 27, 2025 | 5.3 | 17 | NO | NO |
CVE-2022-34013MEDIUM OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module. | Jun 23, 2022 | 4.3 | 17 | NO | NO |
CVE-2022-34012MEDIUM Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges. | Jun 23, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zhyd.
Media articles that mention a CVE ID that affects a product developed by Zhyd — matched by CVE ID, not by vendor name.