CVE-2025-36560: Appleple A-Blog CMS

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.

Affected products

  • Appleple A-Blog CMS: from 2.8.0, up to and including 2.8.85; from 2.9.0, up to and including 2.9.52; from 2.10.0, up to and including 2.10.63; from 2.11.0, up to and including 2.11.75; from 3.0.0, up to and including 3.0.47; from 3.1.0, up to and including 3.1.43

Published 2025-05-19. Last modified 2026-06-17.