VYPR
High severity8.5NVD Advisory· Published Feb 8, 2022· Updated Jun 17, 2026

CVE-2022-23626

CVE-2022-23626

Description

m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions imagecreatefrom* and image* have not been checked properly. Although PHP issued warnings and the upload function returned false, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • M1k1o/Blogllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: < 1.4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.