Home/Product/mtons mblog
Product

mtons mblog

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-9647
<= 3.5.0
A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list
4.3MEDIUM
CVE-2025-9433
<= 3.5.0
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of
4.3MEDIUM
CVE-2025-9432
<= 3.5.0
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/lis
4.3MEDIUM
CVE-2025-9431
<= 3.5.0
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the ar
4.3MEDIUM
CVE-2025-9430
<= 3.5.0
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/upd
2.4LOW
CVE-2025-9429
<= 3.5.0
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/s
3.5LOW
CVE-2025-9407
<= 3.5.0
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings
3.5LOW
CVE-2025-9005
<= 3.5.0
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation
3.7LOW
CVE-2025-9004
<= 3.5.0
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. T
3.7LOW
CVE-2025-8992
<= 3.5.0
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation
4.3MEDIUM
CVE-2025-8927
<= 3.5.0
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email
3.7LOW
CVE-2024-13199
all versions
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unkno
3.5LOW
CVE-2024-13198
all versions
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of th
3.7LOW
CVE-2024-28713
all versions
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feat
9.8CRITICAL
CVE-2021-27280
all versions
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets select
7.8HIGH
CVE-2021-46028
<= 3.5.0
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once th
4.3MEDIUM
CVE-2020-19619
all versions
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
5.4MEDIUM
CVE-2020-19618
all versions
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
5.4MEDIUM
CVE-2020-19617
all versions
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
5.4MEDIUM
CVE-2020-19616
all versions
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
5.4MEDIUM
CVE-2007-6582
all versions
Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in
threatengine.sh