CVE-2025-9431
MEDIUMmtons mblog <3.5.0 - XSS
Title source: llmDescription
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
Exploits (1)
Scores
CVSS v3
4.3
EPSS
0.0004
EPSS Percentile
11.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-94
CWE-79
Status
published
Products (1)
mtons/mblog
< 3.5.0
Published
Aug 26, 2025
Tracked Since
Feb 18, 2026