Cyber Resilience

CVE-2024-23348

Appleple A-Blog Cms ≤ 2.9.0

Published
23 January 2024
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0069 50th percentile
Risk Priority 66 floored blend · peak EPSS

Summary

CVE-2024-23348 is a high-severity an unspecified weakness vulnerability in Appleple A-Blog Cms. Its CVSS base score is 8.8 (High).

Operationally, ranked at the 50th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Improper input validation vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier allows a remote authenticated attacker…

more

to execute arbitrary JavaScript code by uploading a specially crafted SVG file.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-30419Same product: Appleple A-Blog Cms
CVE-2024-31395Same product: Appleple A-Blog Cms
CVE-2025-41429Same product: Appleple A-Blog Cms
CVE-2025-27566Same product: Appleple A-Blog Cms
CVE-2024-23182Same product: Appleple A-Blog Cms
CVE-2025-31103Same product: Appleple A-Blog Cms
CVE-2024-27279Same product: Appleple A-Blog Cms
CVE-2024-23181Same product: Appleple A-Blog Cms
CVE-2024-23180Same product: Appleple A-Blog Cms
CVE-2024-25559Same product: Appleple A-Blog Cms

Affected Assets

appleple
a-blog cms
≤ 2.9.0 · 2.10.0 — 2.10.50 · 2.11.0 — 2.11.58

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References