Blogotext Project
blogotext_project
4 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Blogotext Project 1Blogotext May 13, 2026 Dec 20, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address field. |
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on W...Show more |
1Blogotext Project 1Blogotext May 13, 2026 Dec 20, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment. |
1Blogotext Project 1Blogotext May 13, 2026 Oct 2, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global set...Show more |