VYPR

ForestBlog

by saysky

CVEs (2)

  • CVE-2023-6887MedDec 17, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to…

  • CVE-2024-57498MedFeb 3, 2025
    risk 0.31cvss 4.8epss 0.00

    Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function.