VendorsForestblog Projectforestblogany version
Vulnerabilities

Forestblog Project Forestblog any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-46033
In ForestBlog, as of 2021-12-28, File upload can bypass verification.
Published 2022-01-25 · Modified
9.8EPSS 0.012
CVE-2023-6887
saysky ForestBlog Image Upload img unrestricted upload
Published 2023-12-17 · Modified
9.8EPSS 0.009
CVE-2021-46034
A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickname input box.
Published 2022-01-25 · Modified
6.1EPSS 0.006
CVE-2022-29020
ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.
Published 2022-04-15 · Modified
6.1EPSS 0.006
CVE-2025-3004
Sayski ForestBlog search cross site scripting
Published 2025-03-31 · Analyzed
5.4EPSS 0.003
CVE-2025-3005
Sayski ForestBlog Friend Link cross site scripting
Published 2025-03-31 · Analyzed
5.4EPSS 0.003