PT-2026-68352 · Oblog · Oblog

·

CVE-2026-18968

·

Published

2026-08-05

·

Updated

2026-08-06

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ttttonyhe OBlog versions up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f
Description Remote attackers can perform cross site scripting (XSS) through the improper processing of the /tags.php endpoint. This occurs when the day argument is manipulated, allowing the execution of malicious scripts in the victim's browser.
Recommendations Update ttttonyhe OBlog to a version later than 3ca6a45a2fcc81f6086751d8af124658720e8f8f. As a temporary workaround, restrict access to the /tags.php file or avoid using the day argument until a fix is applied.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18968

Affected Products

Oblog