CVE-2025-41429: Appleple A-Blog CMS

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.

Affected products

  • Appleple A-Blog CMS: from 2.8.0, up to and including 2.8.85; from 2.9.0, up to and including 2.9.52; from 2.10.0, up to and including 2.10.63; from 2.11.0, up to and including 2.11.75; from 3.0.0, up to and including 3.0.47; from 3.1.0, up to and including 3.1.43

Published 2025-05-19. Last modified 2026-06-17.