← Back

B3log

b3log

70 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Siyuan
siyuan
Symphony
symphony
Vditor
vditor
Solo
solo
Wide
wide

CVEs (70)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1B3log
1Vditor
Jun 17, 2026
Mar 14, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
1B3log
1Vditor
Jun 17, 2026
Jan 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
1B3log
1Symphony
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
1B3log
1Wide
Jun 17, 2026
Jul 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the a...Show more
b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in the editor, and compile and run it approximately three times to read an arbitrary file. Second, the attacker can create a symlink, and then place the symlink into a ZIP archive. An unzip operation leads to read access, and write access (depending on file permissions), to the symlink target. Third, the attacker can import a Git repository that contains a symlink, similarly leading to read and write access.Show less
1B3log
1Solo
Nov 21, 2024
Jun 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a careful...Show more
b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows remote attackers to inject arbitrary Web scripts or HTML via a carefully crafted site name in an admin-authenticated HTTP request.Show less
1B3log
1Symphony
Nov 21, 2024
Jun 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote...Show more
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web site name.Show less
1B3log
1Symphony
Jun 17, 2026
Feb 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
1B3log
1Solo
Nov 21, 2024
Sep 10, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name...Show more
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.Show less
1B3log
1Symphony
Nov 21, 2024
Apr 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
1B3log
1Symphony
May 13, 2026
Nov 15, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/us...Show more
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid.Show less