Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-37271

Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Nelson Print My Blog allows Stored XSS.This issue affects Print My Blog: from n/a through 3.27.0.
Attacker Value
Unknown

CVE-2023-29639

Disclosure Date: May 01, 2023 (last updated October 08, 2023)
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString.
Attacker Value
Unknown

CVE-2023-29636

Disclosure Date: May 01, 2023 (last updated October 08, 2023)
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
Attacker Value
Unknown

CVE-2023-1937

Disclosure Date: April 07, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-225264.
Attacker Value
Unknown

CVE-2023-27093

Disclosure Date: March 13, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.
Attacker Value
Unknown

CVE-2021-24636

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make logged in administrators deactivate the Print My Blog plugin and delete all saved data for that plugin by tricking them to open a malicious link
Attacker Value
Unknown

CVE-2019-11565

Disclosure Date: April 27, 2019 (last updated November 27, 2024)
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
0