Description
Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'.
No analysis available yet.
Remediation
Vendor Solution
Upgrade Alma Blog to version 2.2.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16915 | Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could allow an attacker to store a malicious JavaScript payload within the application by adding the payload to 'Community Description' or 'Community Rules'. |
References
History
Wed, 15 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alma
Alma alma Blog |
|
| CPEs | cpe:2.3:a:alma:alma_blog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alma
Alma alma Blog |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T18:26:30.513Z
Reserved: 2024-02-01T08:39:01.177Z
Link: CVE-2024-1146
Updated: 2024-08-01T18:26:30.513Z
Status : Analyzed
Published: 2024-03-19T12:15:08.443
Modified: 2025-10-15T18:04:10.433
Link: CVE-2024-1146
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:40Z
Weaknesses
EUVD