Vulnerabilities and security researches forbluff-post bluff-post
Direction: ascendingJul 02, 2025
Bluff Post # CVE-2025-52784
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 20, 2025
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in hideoguchi Bluff Post bluff-post allows Stored XSS.This issue affects Bluff Post: from n/a through <= 1.1.1.
- Affected versions
-
max 1.1.1.
- Status
-
vulnerable
Sep 28, 2026
Bluff Post # CVE-2026-89237
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 26, 2026
- Research Description
- The Bluff Post WordPress plugin through 1.1.1 does not sanitise and escape parameters before using them as identifiers in a SQL query, allowing unauthenticated attackers to append additional SQL and extract sensitive information from the database.
- Affected versions
-
max 1.1.1.
- Status
-
vulnerable