VendorsZhydoneblogany version
Vulnerabilities

Zhyd OneBlog any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-60355
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
Published 2025-10-28 · Modified
9.8EPSS 0.005
CVE-2024-54954
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
Published 2025-02-10 · Analyzed
8.0EPSS 0.004
CVE-2025-2833
zhangyd-c OneBlog HTTP Header redos
Published 2025-03-27 · Analyzed
6.9EPSS 0.007
CVE-2025-2835
zhangyd-c OneBlog RestApiController.java autoLink server-side request forgery
Published 2025-03-27 · Analyzed
5.3EPSS 0.003