← Back

Anecms Blog

anecms_blog

Vendor: Anecms • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anecms
1Anecms Blog
Apr 29, 2026
Jun 24, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.
1Anecms
1Anecms Blog
Apr 29, 2026
Jun 24, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.