Known Vulnerabilities for Oneblog by Oneblog Project
Listed below are 2 of the newest known vulnerabilities associated with "Oneblog" by "Oneblog Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-51937 json | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTick... | Not Provided | 2026-07-07 | 2026-07-08 |
| CVE-2021-46085 json | OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond ... | 6.5 - MEDIUM | 2022-01-25 | 2022-01-31 |
| CVE-2021-46025 json | A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the ... | 5.4 - MEDIUM | 2022-01-19 | 2022-01-25 |