CVE-2019-7587: Bo-Blog Bw

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function.

Affected products

  • Bo-Blog Bw: up to and including 1.6.0-r

Published 2019-02-07. Last modified 2026-06-17.