VYPR

A Blog CMS

by Appleple

CVEs (26)

  • CVE-2024-23782MedJan 28, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier…

  • CVE-2024-23183MedJan 23, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a…

  • CVE-2025-41429MedMay 19, 2025
    risk 0.31cvss 4.8epss 0.00

    a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.

  • CVE-2024-25559MedFeb 15, 2024
    risk 0.31cvss 4.7epss 0.00

    URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.

  • CVE-2024-30420MedMay 22, 2024
    risk 0.29cvss 4.4epss 0.00

    Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the…

  • CVE-2025-27566LowMay 19, 2025
    risk 0.25cvss 3.8epss 0.00

    Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited,…

Page 2 of 2