📦 Flaskblog

by Dogukanurker

🔍 What is Flaskblog?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-28104

CRITICAL CVSS 9.1 Apr 21, 2025

An incorrect access control vulnerability in flaskBlog v2.6.1 allows unauthenticated attackers to retrieve all usernames via crafted input. This affects all deployments using the vulnerable version, p...

CVE-2025-55737

MEDIUM CVSS 6.5 Aug 19, 2025

This vulnerability in flaskBlog allows any authenticated user to delete arbitrary comments belonging to other users by manipulating the commentID parameter in delete requests. It affects all users of ...

CVE-2025-55734

MEDIUM CVSS 6.5 Aug 19, 2025

This CVE describes an authorization bypass vulnerability in flaskBlog where admin role checks are only performed on the main /admin route but not on subroutes like /admin/posts and /admin/comments. Th...

CVE-2025-55735

MEDIUM CVSS 5.4 Aug 19, 2025

This stored cross-site scripting (XSS) vulnerability in flaskBlog allows attackers to inject malicious scripts into blog posts that execute when other users view those posts. All users of flaskBlog ve...

CVE-2025-55736

MEDIUM CVSS 6.5 Aug 19, 2025

In flaskBlog versions 2.8.0 and earlier, any authenticated user can escalate their privileges to admin by exploiting a vulnerability in the admin panel user management. This allows unauthorized admini...

CVE-2025-28103

MEDIUM CVSS 6.4 Apr 21, 2025

This vulnerability in flaskBlog v2.6.1 allows attackers to delete arbitrary user accounts without proper authorization. Attackers can exploit incorrect access control by sending specially crafted requ...

CVE-2025-28102

MEDIUM CVSS 6.1 Apr 21, 2025

A stored cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to inject malicious scripts into blog posts via the postContent parameter. This affects all users running the vul...