CVE-2025-9433
MEDIUMmtons mblog <3.5.0 - XSS
Title source: llmDescription
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
Exploits (1)
Scores
CVSS v3
4.3
EPSS
0.0004
EPSS Percentile
11.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Details
CWE
CWE-94
CWE-79
Status
published
Products (1)
mtons/mblog
< 3.5.0
Published
Aug 26, 2025
Tracked Since
Feb 18, 2026