İçeriğe atla
Noroxi

zhyd kayıtları

zhyd üreticisine ait 14 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

14 kayıt
  • CVE-2025-60355
    39İzleyin

    zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

    KritikCVSS 9,8İstismar yokEPSS %0

    zhyd · oneblog28 Eki 2025

  • CVE-2024-54954
    32İzleyin

    OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

    YüksekCVSS 8,0İstismar yokEPSS %0

    zhyd · oneblog10 Şub 2025

  • CVE-2025-56264
    30İzleyin

    The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

    YüksekCVSS 7,5İstismar yokEPSS %0

    zhyd · oneblog16 Eyl 2025

  • CVE-2025-2833
    27İzleyin

    zhangyd-c OneBlog HTTP Header redos

    OrtaCVSS 6,9İstismar yokEPSS %1

    zhyd · oneblog27 Mar 2025

  • CVE-2022-34012
    26İzleyin

    Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater

    OrtaCVSS 6,5İstismar yokEPSS %1

    zhyd · oneblog23 Haz 2022

  • CVE-2024-29469
    24İzleyin

    A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted

    OrtaCVSS 6,1İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2024-29470
    24İzleyin

    OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.

    OrtaCVSS 6,1İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2024-29473
    24İzleyin

    OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.

    OrtaCVSS 6,1İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2024-29474
    21İzleyin

    OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.

    OrtaCVSS 5,4İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2024-29471
    21İzleyin

    OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.

    OrtaCVSS 5,4İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2024-29472
    21İzleyin

    OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.

    OrtaCVSS 5,4İstismar yokEPSS %0

    zhyd · oneblog20 Mar 2024

  • CVE-2025-2835
    21İzleyin

    zhangyd-c OneBlog RestApiController.java autoLink server-side request forgery

    OrtaCVSS 5,3İstismar yokEPSS %0

    zhyd · oneblog27 Mar 2025

  • CVE-2022-34011
    17İzleyin

    OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.

    OrtaCVSS 4,3İstismar yokEPSS %1

    zhyd · oneblog23 Haz 2022

  • CVE-2022-34013
    17İzleyin

    OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.

    OrtaCVSS 4,3İstismar yokEPSS %1

    zhyd · oneblog23 Haz 2022