CVE-2023-33404: Blogengine Blogengine.net
Critical severity, CVSS 9.8. EPSS: 25.8% chance of exploitation in the next 30 days.
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
Affected products
- Blogengine Blogengine.net: up to and including 3.3.8.0
Published 2023-06-26. Last modified 2026-06-17.