CVE-2013-6953: Dotnetblogengine Blogengine.net

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.

Affected products

  • Dotnetblogengine Blogengine.net: up to and including 2.8; version 1.4.5 only; version 1.5 only; version 1.6 only; version 2.0 only; version 2.5 only; …

Published 2014-01-03. Last modified 2026-06-17.