Vulnerabilities (CVE)

Filtered by vendor Appleple Subscribe
Filtered by product A-blog Cms
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1178 1 Appleple 1 A-blog Cms 2017-04-20 6.4 MEDIUM 6.5 MEDIUM
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
CVE-2016-1179 1 Appleple 1 A-blog Cms 2017-04-20 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.