← Back

Miniblog.core Project

miniblog.core_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Miniblog.core
miniblog.core

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Miniblog.core Project
1Miniblog.core
Jun 17, 2026
Sep 2, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inje...Show more
Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Excerpt field.Show less
1Miniblog.core Project
1Miniblog.core
Jun 17, 2026
Apr 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64...Show more
madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in Controllers/BlogController.cs writes a decoded base64 string to a file without validating the extension.Show less