VYPR

Magento 2 Blog

by Mageplaza

CVEs (1)

  • CVE-2026-79322HigSep 9, 2026
    risk 0.56cvss 8.6epss

    SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.