CVE-2024-31396: Appleple A-Blog CMS
Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an arbitrary command on the server.
Affected products
- Appleple A-Blog CMS: from 3.0.0, before 3.0.32 (fixed in 3.0.32); from 3.1.0, before 3.1.12 (fixed in 3.1.12)
Published 2024-05-22. Last modified 2026-06-17.