← Back

Oneblog

oneblog

Vendor: Zhyd • 14 CVEs

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zhyd
1Oneblog
Jun 17, 2026
Oct 28, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
1Zhyd
1Oneblog
Jun 17, 2026
Sep 16, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 27, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The man...Show more
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Zhyd
1Oneblog
Jun 17, 2026
Mar 27, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For le...Show more
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.Show less
1Zhyd
1Oneblog
Jun 17, 2026
Feb 10, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.
1Zhyd
1Oneblog
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module.
1Zhyd
1Oneblog
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
1Zhyd
1Oneblog
Jun 17, 2026
Jun 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
1Zhyd
1Oneblog
Jun 17, 2026
Jun 23, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.