VYPR
High severity8.5NVD Advisory· Published Feb 8, 2022· Updated Jun 17, 2026

CVE-2022-23626

CVE-2022-23626

Description

m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions imagecreatefrom* and image* have not been checked properly. Although PHP issued warnings and the upload function returned false, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:blog_project:blog:*:*:*:*:*:*:*:*
    Range: <1.4
  • M1k1o/Blogv52 versions
    < 1.4+ 1 more
    • (no CPE)range: < 1.4
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.