CVE-2018-14485: Blogengine Blogengine.net

Critical severity, CVSS 9.8. EPSS: 16.3% chance of exploitation in the next 30 days.

BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

Affected products

Published 2019-05-07. Last modified 2026-06-17.