Releases5
Frequency1 year 4 months
Last Release
Stars584
开源免费的Java博客系统, 采用spring-boot、spring-data-jpa、shiro、freemarker、bootstrap等框架, 支持Docker

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH

OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.

4.3 MEDIUM4.3 MEDIUM

In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.

5.4 MEDIUM3.5 LOW

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.

5.4 MEDIUM3.5 LOW

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.

5.4 MEDIUM3.5 LOW

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.

5.4 MEDIUM3.5 LOW

Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.