CVE-2025-41429: Appleple A-Blog CMS
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
Affected products
- Appleple A-Blog CMS: from 2.8.0, up to and including 2.8.85; from 2.9.0, up to and including 2.9.52; from 2.10.0, up to and including 2.10.63; from 2.11.0, up to and including 2.11.75; from 3.0.0, up to and including 3.0.47; from 3.1.0, up to and including 3.1.43
Published 2025-05-19. Last modified 2026-06-17.