Nibbleblog

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-23356

    dmin/kernel/api/login.class.phpin in nibbleblog v3.7.1c allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

    Last Modified: Nov 21, 2024
    Published: Jan 27, 2021

    CVE-2019-7719

    Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2019

    CVE-2018-16604

    An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").

    Last Modified: Nov 21, 2024
    Published: Sep 06, 2018

    CVE-2018-6470

    Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.

    Last Modified: Nov 21, 2024
    Published: Feb 01, 2018

    CVE-2015-6966

    Multiple cross-site request forgery (CSRF) vulnerabilities in Nibbleblog before 4.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) create a post via a new_simple action to admin.php or (2) conduct cross-site scripting (XSS) attacks via the content parameter in a new_simple action to admin.php.

    Last Modified: Apr 12, 2025
    Published: Sep 16, 2015
    Items Per Page