Vulnerabilities > Blogengine > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-26 CVE-2023-33404 Unrestricted Upload of File with Dangerous Type vulnerability in Blogengine Blogengine.Net
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
network
low complexity
blogengine CWE-434
critical
9.8
2023-01-18 CVE-2022-41417 Missing Authorization vulnerability in Blogengine Blogengine.Net 3.3.8.0
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
network
low complexity
blogengine CWE-862
critical
9.8
2022-05-13 CVE-2022-25591 Path Traversal vulnerability in Blogengine Blogengine.Net 3.3.8.0
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
network
low complexity
blogengine CWE-22
critical
9.1
2019-05-07 CVE-2018-14485 XXE vulnerability in Blogengine Blogengine.Net 3.3
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
network
low complexity
blogengine CWE-611
critical
9.8
2019-03-21 CVE-2019-6714 Path Traversal vulnerability in Blogengine Blogengine.Net 3.3/3.3.5.0/3.3.6.0
An issue was discovered in BlogEngine.NET through 3.3.6.0.
network
low complexity
blogengine CWE-22
critical
9.8