← Back

Pyblosxom

pyblosxom

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pyblosxom
pyblosxom

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pyblosxom
1Pyblosxom
Apr 16, 2026
Jun 7, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Contributed Packages for PyBlosxom 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the Comments plugin in the (1) url and (2) author fi...Show more
Cross-site scripting (XSS) vulnerability in the Contributed Packages for PyBlosxom 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the Comments plugin in the (1) url and (2) author fields.Show less
1Pyblosxom
1Pyblosxom
Apr 16, 2026
Feb 15, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.