Skip to content
Noroxi

blogengine records

14 published records for vendor blogengine.

All records

14 records
  • An issue was discovered in BlogEngine.NET through 3.3.6.0.

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    blogengine · blogengine.netMar 21, 2019

  • An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earl

    CriticalCVSS 9.8Proof of conceptEPSS 26%

    blogengine · blogengine.netJun 26, 2023

  • BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    blogengine · blogengine.netMay 7, 2019

  • BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.

    CriticalCVSS 9.8No exploitEPSS 1%

    blogengine · blogengine.netJan 18, 2023

  • BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager.

    HighCVSS 8.8No exploitEPSS 7%

    blogengine · blogengine.netJun 21, 2019

  • BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the

    CriticalCVSS 9.1No exploitEPSS 3%

    blogengine · blogengine.netMay 13, 2022

  • Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

    MediumCVSS 6.1Proof of conceptEPSS 31%

    blogengine · blogengine.netJun 21, 2023

  • CVE-2014-4736
    31Monitor

    SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @

    HighCVSS 7.5Proof of conceptEPSS 2%

    blogengine · e2Jul 24, 2014

  • An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute a

    HighCVSS 7.2No exploitEPSS 1%

    blogengine · blogengine.netDec 19, 2022

  • A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary f

    MediumCVSS 6.5No exploitEPSS 1%

    blogengine · blogengine.netMay 18, 2022

  • Stored cross-site scripting in BlogEngine.NET version 3.3.8.0

    MediumCVSS 5.3No exploitEPSS 0%

    blogengine · blogengine.netMar 6, 2023

  • Stored cross-site scripting in BlogEngine.NET version 3.3.8.0

    MediumCVSS 5.4No exploitEPSS 0%

    blogengine · blogengine.netMar 6, 2023

  • Stored cross-site scripting in BlogEngine.NET version 3.3.8.0

    MediumCVSS 5.4No exploitEPSS 0%

    blogengine · blogengine.netMar 6, 2023

  • BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts.

    MediumCVSS 4.8No exploitEPSS 1%

    blogengine · blogengine.netSep 2, 2022