Vulnerabilities (CVE)

Filtered by vendor Alma Subscribe
Filtered by product Alma Blog
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1144 1 Alma 1 Alma Blog 2025-10-15 N/A 6.5 MEDIUM
Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an unauthenticated user to access the application's functionalities without the need for credentials.
CVE-2024-1145 1 Alma 1 Alma Blog 2025-10-15 N/A 5.3 MEDIUM
User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow a remote user to retrieve all valid users registered in the application just by looking at the request response.
CVE-2024-1146 1 Alma 1 Alma Blog 2025-10-15 N/A 5.8 MEDIUM
Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.