CVE-2025-13181: h3blog
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/material/add. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
- h3blog h3blog: version 1.0.0 only
Published 2025-11-14. Last modified 2026-10-07.