Blogengine / Blogengine.net
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-33404 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote a… | CRITICAL | 9.8 | Jun 26, 2023 |
| CVE-2023-33405 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | MEDIUM | 6.1 | Jun 21, 2023 |
| CVE-2023-22858 | Stored cross-site scripting in BlogEngine.NET version 3.3.8.0 | MEDIUM | 5.3 | Mar 6, 2023 |
| CVE-2023-22857 | Stored cross-site scripting in BlogEngine.NET version 3.3.8.0 | HIGH | 8.5 | Mar 6, 2023 |
| CVE-2023-22856 | Stored cross-site scripting in BlogEngine.NET version 3.3.8.0 | HIGH | 8.5 | Mar 6, 2023 |
| CVE-2022-41417 | BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. | CRITICAL | 9.8 | Jan 18, 2023 |
| CVE-2022-41418 | An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via u… | HIGH | 7.2 | Dec 19, 2022 |
| CVE-2022-36600 | BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows atta… | MEDIUM | 4.8 | Sep 2, 2022 |
| CVE-2022-28921 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting… | MEDIUM | 6.5 | May 18, 2022 |
| CVE-2022-25591 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root di… | CRITICAL | 9.1 | May 13, 2022 |
| CVE-2019-10720 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists becau… | HIGH | 8.8 | Jun 21, 2019 |
| CVE-2018-14485 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | CRITICAL | 9.8 | May 7, 2019 |
| CVE-2019-6714 | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticate… | CRITICAL | 9.8 | Mar 17, 2019 |
Showing 1 to 13 of 13 CVEs