CVE-2019-9765: Blog Mini Project Blog Mini

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.

Affected products

Published 2019-03-14. Last modified 2026-06-17.