Vulnerabilities > Blogengine > E2 > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-07-24 | CVE-2014-4736 | SQL Injection vulnerability in Blogengine E2 2.4 SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process. | 7.5 |