Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blogengine.net CRITICAL 9.8
CVE-2023-33404EPSS 26%

An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allow…

Fix: after 3.3.8.0
Fix from $2,300 2023-06-26
Blogengine.net MEDIUM 6.1
CVE-2023-33405EPSS 31%

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

Fix: after 3.3.8.0
Fix from $1,600 2023-06-21
Blogengine.net MEDIUM 5.3
CVE-2023-22858

An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.

Mitigation only
Fix from $1,600 2023-03-06
Blogengine.net MEDIUM 5.4
CVE-2023-22856

A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a bl…

Mitigation only
Fix from $1,600 2023-03-06
Blogengine.net MEDIUM 5.4
CVE-2023-22857

A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a bl…

Mitigation only
Fix from $1,600 2023-03-06
Blogengine.net CRITICAL 9.8
CVE-2022-41417

BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.

Patch available
Fix from $2,300 2023-01-18
Blogengine.net HIGH 7.2
CVE-2022-41418

An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary …

Patch available
Fix from $1,950 2022-12-19
Blogengine.net MEDIUM 6.5
CVE-2022-28921

A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on t…

No fix yet
Fix from $1,600 2022-05-18
Blogengine.net CRITICAL 9.1
CVE-2022-25591

BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web serv…

No fix yet
Fix from $2,300 2022-05-13
Blogengine.net HIGH 8.8
CVE-2019-10720EPSS 7%

BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue ex…

Fix: after 3.3.7.0
Fix from $1,950 2019-06-21
Blogengine.net CRITICAL 9.8
CVE-2018-14485EPSS 16%

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

No fix yet
Fix from $2,300 2019-05-07
Blogengine.net CRITICAL 9.8
CVE-2019-6714EPSS 32%

An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unau…

Fix: after 3.3.6.0
Fix from $2,300 2019-03-21
E2 HIGH 7.5
CVE-2014-4736

SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/c…

Fix: after 2.4
Fix from $1,950 2014-07-24