CVE-2025-31103: Appleple A-Blog CMS
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server.
Affected products
- Appleple A-Blog CMS: up to and including 2.8.80; from 2.9.0, up to and including 2.9.46; from 2.10.0, before 2.10.58 (fixed in 2.10.58); from 2.11.0, before 2.11.70 (fixed in 2.11.70); from 3.0.0, before 3.0.41 (fixed in 3.0.41); from 3.1.0, before 3.1.37 (fixed in 3.1.37)
Published 2025-03-31. Last modified 2026-06-17.