Home/Product/dogukanurker flaskblog
Product

dogukanurker flaskblog

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55737
<= 2.8.0
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of
6.5MEDIUM
CVE-2025-55736
<= 2.8.0
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relat
6.5MEDIUM
CVE-2025-55735
<= 2.8.0
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the
5.4MEDIUM
CVE-2025-55734
<= 2.8.0
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the
6.5MEDIUM
CVE-2025-53631
<= 2.8.1
flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST r
5.4MEDIUM
CVE-2025-28104
all versions
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
9.1CRITICAL
CVE-2025-28103
all versions
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
6.4MEDIUM
CVE-2025-28102
all versions
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a cra
6.1MEDIUM
CVE-2025-28101
all versions
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article
6.5MEDIUM
CVE-2024-22414
<= 1.1.0
flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the /user/<user> page allows a user's comment
6.5MEDIUM
threatengine.sh