a-blog cms multiple versions neutralize logs improperly. If this vulnerability is exploited with CVE-2025-36560, a remote unauthenticated attacker may hijack a legitimate user's session.
| Software | From | Fixed in |
|---|---|---|
| appleple / a-blog_cms | 2.8.0 | 2.8.85.x |
| appleple / a-blog_cms | 2.9.0 | 2.9.52.x |
| appleple / a-blog_cms | 2.10.0 | 2.10.63.x |
| appleple / a-blog_cms | 2.11.0 | 2.11.75.x |
| appleple / a-blog_cms | 3.0.0 | 3.0.47.x |
| appleple / a-blog_cms | 3.1.0 | 3.1.43.x |