Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Mblog Project:
>> Mblog
>> 3.5.0
Security Vulnerabilities
CVE-2021-27280
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
CVSS Score
7.8
EPSS Score
0.0
Published
2023-05-08
CVE-2021-46028
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
CVSS Score
4.3
EPSS Score
0.001
Published
2022-01-20
CVE-2020-19618
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-04-01
CVE-2020-19619
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-04-01
CVE-2020-19616
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-04-01
CVE-2020-19617
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
CVSS Score
5.4
EPSS Score
0.002
Published
2021-04-01
Page 1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved