CVE-2025-36560: Appleple A-Blog CMS
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Server-side request forgery vulnerability exists in a-blog cms multiple versions. If this vulnerability is exploited, a remote unauthenticated attacker may gain access to sensitive information by sending a specially crafted request.
Affected products
- Appleple A-Blog CMS: from 2.8.0, up to and including 2.8.85; from 2.9.0, up to and including 2.9.52; from 2.10.0, up to and including 2.10.63; from 2.11.0, up to and including 2.11.75; from 3.0.0, up to and including 3.0.47; from 3.1.0, up to and including 3.1.43
Published 2025-05-19. Last modified 2026-06-17.