cvedb.io
CVE-2025-27566
LOW · CVSS 3.8
EPSS exploitation probability: 0%
Published 2025-05-19T09:15:24.627 · Last modified 2026-06-17T09:03:48.830

Summary

Path traversal vulnerability exists in a-blog cms versions prior to Ver. 3.1.43 and versions prior to Ver. 3.0.47. This is an issue with insufficient path validation in the backup feature, and exploitation requires the administrator privilege. If this vulnerability is exploited, a remote authenticated attacker with the administrator privilege may obtain or delete any file on the server.

Affected products

appleple — a-blog_cms

Does this affect you?

Add your gear to cvedb and we'll alert you only when appleple ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.