Skip to main content

CVE detail

CVE-2025-60355

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

CVSS 9.8 · Critical