Javaweb Blog ProjectCVEs & Vulnerabilities
2 CVEs affecting Javaweb Blog Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
javaweb blog 2
CVE-2022-40037CRITICAL
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
27 Jan 2023
9.8
CVSS
CVE-2022-40034MEDIUM
Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.
24 Jan 2023
5.4
CVSS
← PrevPage 1 / 1Next →