VYPR

OneBlog

by zhangyd-c

CVEs (2)

  • CVE-2025-60355Oct 28, 2025
    risk 0.00cvss epss 0.00

    zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

  • CVE-2025-56264Sep 16, 2025
    risk 0.00cvss epss 0.00

    The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.