bblog CVE Vulnerabilities & CVE List (2)

Products (CPE): — CVEs: 2

bblog vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to bblog, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-4436 SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter. [email protected] 7.5 0.97% 2008-10-03 2026-04-23
CVE-2004-1865 Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates, then this issue would not give any additional privileges, and thus would not be considered a vulnerability. [email protected] 4.8 0.96% 2004-03-26 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence