Vulnerabilities > Blogengine > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-26 | CVE-2023-33404 | Unrestricted Upload of File with Dangerous Type vulnerability in Blogengine Blogengine.Net An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | 9.8 |
2023-01-18 | CVE-2022-41417 | Missing Authorization vulnerability in Blogengine Blogengine.Net 3.3.8.0 BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. | 9.8 |
2022-05-13 | CVE-2022-25591 | Path Traversal vulnerability in Blogengine Blogengine.Net 3.3.8.0 BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. | 9.1 |
2019-05-07 | CVE-2018-14485 | XXE vulnerability in Blogengine Blogengine.Net 3.3 BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | 9.8 |
2019-03-21 | CVE-2019-6714 | Path Traversal vulnerability in Blogengine Blogengine.Net 3.3/3.3.5.0/3.3.6.0 An issue was discovered in BlogEngine.NET through 3.3.6.0. | 9.8 |