Showing 2 vulnerabilities on this page for SmartBlog

Signals CISA KEV Ransomware Nuclei
SmartDataSoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SmartBlog 2.0.1 - 'id_post' Blind SQL injection

SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information.

CWE-89Jan 28, 2026
CVSS8.8v4.0EPSS0.282%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

smartdatasoft smartblog Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Multiple SQL injection vulnerabilities in SmartDataSoft SmartBlog for PrestaShop before 4.06 allow a remote unauthenticated attacker to execute arbitrary SQL commands via the day, month, or year parameter to the controllers/front/archive.php archive controller, or the id_category parameter to the controllers/front/category.php category controller.

CWE-89Aug 24, 20211 related artifact
CVSS9.8v3.1EPSS74.5%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX