CVE-2024-39150: b3log Vditor

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.

Affected products

  • b3log Vditor: up to and including 3.9.8

Published 2024-07-05. Last modified 2026-06-17.