Adlered Bolo-Solo vulnerabilities
6 known vulnerabilities affecting adlered/bolo-solo.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3
Vulnerabilities
Page 1 of 1
CVE-2026-1813P2CRITICALCVSS 9.8≤ 2.6.42026-02-04
CVE-2026-1813 [CRITICAL] CWE-284 CVE-2026-1813: A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the
A vulnerability was found in bolo-blog bolo-solo up to 2.6.4. Affected is an unknown function of the file src/main/java/org/b3log/solo/bolo/pic/PicUploadProcessor.java of the component FreeMarker Template Handler. The manipulation of the argument File results in unrestricted upload. It is possible to launch the attack remotely. The exploit has been
nvd
CVE-2026-1812P3CRITICALCVSS 9.8≤ 2.6.42026-02-03
CVE-2026-1812 [CRITICAL] CWE-22 CVE-2026-1812: A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importF
A vulnerability has been found in bolo-blog bolo-solo up to 2.6.4. This impacts the function importFromCnblogs of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. The manipulation of the argument File leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disc
nvd
CVE-2026-1691P3HIGHCVSS 8.8≤ 2.6.4v2.6.0+4 more2026-01-30
CVE-2026-1691 [HIGH] CWE-20 CVE-2026-1691: A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSy
A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-1811P3HIGHCVSS 8.8≤ 2.6.42026-02-03
CVE-2026-1811 [HIGH] CWE-22 CVE-2026-1811: A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdo
A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The exploit has been published an
nvd
CVE-2026-1810P3HIGHCVSS 8.8≤ 2.6.42026-02-03
CVE-2026-1810 [HIGH] CWE-22 CVE-2026-1810: A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the functio
A vulnerability was detected in bolo-blog bolo-solo up to 2.6.4. The impacted element is the function unpackFilteredZip of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component ZIP File Handler. Performing a manipulation of the argument File results in path traversal. The attack is possible to be carried out remotely. The ex
nvd
CVE-2023-41009P3CRITICALCVSS 9.8v2.62023-09-05
CVE-2023-41009 [CRITICAL] CWE-434 CVE-2023-41009: File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary c
File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.
nvd