Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flaskblog MEDIUM 6.5
CVE-2025-55737

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every…

Fix: after 2.8.0
Fix from $1,600 2025-08-19
Flaskblog MEDIUM 6.5
CVE-2025-55734

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but no…

Fix: after 2.8.0
Fix from $1,600 2025-08-19
Flaskblog MEDIUM 6.5
CVE-2025-55736

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g…

Fix: after 2.8.0
Fix from $1,600 2025-08-19
Flaskblog MEDIUM 5.4
CVE-2025-55735

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the …

Fix: after 2.8.0
Fix from $1,600 2025-08-19
Flaskblog MEDIUM 5.4
CVE-2025-53631

flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createp…

Fix: after 2.8.1
Fix from $1,600 2025-08-14
Flaskblog CRITICAL 9.1
CVE-2025-28104

Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.

No fix yet
Fix from $2,300 2025-04-21
Flaskblog MEDIUM 6.4
CVE-2025-28103

Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.

Mitigation only
Fix from $1,600 2025-04-21
Flaskblog MEDIUM 6.1
CVE-2025-28102

A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject…

No fix yet
Fix from $1,600 2025-04-21
Flaskblog MEDIUM 6.5
CVE-2025-28101

An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by …

No fix yet
Fix from $1,600 2025-04-17
Flaskblog MEDIUM 5.4
CVE-2024-22414

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitr…

Fix: after 1.1.0
Fix from $1,600 2024-01-17