mtons records
14 published records for vendor mtons.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-307 Improper Restriction of Excessive Authentication Attempts2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-203 Observable Discrepancy1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-28713No exploit | An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.mtons · mblog · CWE-434 | Critical9.8 | — | 1.3% | Mar 28, 2024 |
25Monitor | CVE-2024-13198No exploit | langhsu Mblog Blog System login observable response discrepancymtons · mblog · CWE-203 | Medium6.3 | — | 0.7% | Jan 8, 2025 |
21Monitor | CVE-2024-13199No exploit | langhsu Mblog Blog System Search Bar search cross site scriptingmtons · mblog · CWE-79 | Medium5.3 | — | 0.5% | Jan 8, 2025 |
11Monitor | CVE-2025-9004No exploit | mtons mblog password excessive authenticationmtons · mblog · CWE-307 | Low2.9 | — | 0.9% | Aug 14, 2025 |
11Monitor | CVE-2025-8927No exploit | mtons mblog Verification Code send_code excessive authenticationmtons · mblog · CWE-307 | Low2.9 | — | 0.6% | Aug 13, 2025 |
11Monitor | CVE-2025-9005No exploit | mtons mblog register information exposuremtons · mblog · CWE-200 | Low2.9 | — | 0.6% | Aug 14, 2025 |
8Monitor | CVE-2025-9433No exploit | mtons mblog Admin Panel list cross site scriptingmtons · mblog · CWE-79 | Low2.1 | — | 0.4% | Aug 25, 2025 |
8Monitor | CVE-2025-9432No exploit | mtons mblog Admin Panel list cross site scriptingmtons · mblog · CWE-79 | Low2.1 | — | 0.4% | Aug 25, 2025 |
8Monitor | CVE-2025-9431No exploit | mtons mblog search cross site scriptingmtons · mblog · CWE-79 | Low2.1 | — | 0.4% | Aug 25, 2025 |
8Monitor | CVE-2025-9647No exploit | mtons mblog list cross site scriptingmtons · mblog · CWE-79 | Low2.1 | — | 0.4% | Aug 29, 2025 |
8Monitor | CVE-2025-8992No exploit | mtons mblog cross-site request forgerymtons · mblog · CWE-352 | Low2.1 | — | 0.3% | Aug 14, 2025 |
8Monitor | CVE-2025-9429No exploit | mtons mblog Post submit cross site scriptingmtons · mblog · CWE-79 | Low2.0 | — | 0.3% | Aug 25, 2025 |
8Monitor | CVE-2025-9407No exploit | mtons mblog profile cross site scriptingmtons · mblog · CWE-79 | Low2.0 | — | 0.3% | Aug 25, 2025 |
7Monitor | CVE-2025-9430No exploit | mtons mblog update cross site scriptingmtons · mblog · CWE-79 | Low1.9 | — | 0.3% | Aug 25, 2025 |
- CVE-2024-2871339Monitor
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.
CriticalCVSS 9.8No exploitEPSS 1%mtons · mblogMar 28, 2024
- CVE-2024-1319825Monitor
langhsu Mblog Blog System login observable response discrepancy
MediumCVSS 6.3No exploitEPSS 1%mtons · mblogJan 8, 2025
- CVE-2024-1319921Monitor
langhsu Mblog Blog System Search Bar search cross site scripting
MediumCVSS 5.3No exploitEPSS 0%mtons · mblogJan 8, 2025
- CVE-2025-900411Monitor
mtons mblog password excessive authentication
LowCVSS 2.9No exploitEPSS 1%mtons · mblogAug 14, 2025
- CVE-2025-892711Monitor
mtons mblog Verification Code send_code excessive authentication
LowCVSS 2.9No exploitEPSS 1%mtons · mblogAug 13, 2025
- CVE-2025-900511Monitor
mtons mblog register information exposure
LowCVSS 2.9No exploitEPSS 1%mtons · mblogAug 14, 2025
- CVE-2025-94338Monitor
mtons mblog Admin Panel list cross site scripting
LowCVSS 2.1No exploitEPSS 0%mtons · mblogAug 25, 2025
- CVE-2025-94328Monitor
mtons mblog Admin Panel list cross site scripting
LowCVSS 2.1No exploitEPSS 0%mtons · mblogAug 25, 2025
- CVE-2025-94318Monitor
mtons mblog search cross site scripting
LowCVSS 2.1No exploitEPSS 0%mtons · mblogAug 25, 2025
- CVE-2025-96478Monitor
mtons mblog list cross site scripting
LowCVSS 2.1No exploitEPSS 0%mtons · mblogAug 29, 2025
- CVE-2025-89928Monitor
mtons mblog cross-site request forgery
LowCVSS 2.1No exploitEPSS 0%mtons · mblogAug 14, 2025
- CVE-2025-94298Monitor
mtons mblog Post submit cross site scripting
LowCVSS 2.0No exploitEPSS 0%mtons · mblogAug 25, 2025
- CVE-2025-94078Monitor
mtons mblog profile cross site scripting
LowCVSS 2.0No exploitEPSS 0%mtons · mblogAug 25, 2025
- CVE-2025-94307Monitor
mtons mblog update cross site scripting
LowCVSS 1.9No exploitEPSS 0%mtons · mblogAug 25, 2025