CVE-2019-9765: Blog Mini Project Blog Mini
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, related to app/templates/_article_comments.html.
Affected products
- Blog Mini Project Blog Mini: version 1.0 only
Published 2019-03-14. Last modified 2026-06-17.