CVE-2024-25559: Appleple A-Blog CMS

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.

Affected products

  • Appleple A-Blog CMS: from 3.1.0, up to and including 3.1.8

Published 2024-02-15. Last modified 2026-06-17.