Vulnerabilidades em blinkospace
12 resultadosAnálise Vexday
Blinkospace apresenta 10 vulnerabilidades documentadas, nenhuma em exploração ativa no momento, com a fraqueza dominante sendo path traversal (CWE-22). O portfólio não registra críticas severas nem publicações recentes, indicando risco contido e sem urgência de mitigação imediata.
CVE-2026-23482HIGHBlinko: Unauthorized Arbitrary File Read - /api/file/tempEPSS 1.5%CVE-2026-23483MEDIUMBlinko: Unauthorized Arbitrary File Read - /pluginsEPSS 0.8%CVE-2026-23486MEDIUMBlinko: Unauthorized User Information LeakEPSS 0.7%CVE-2026-85607HIGHBlinko 1.8.7 Cross-User AI Conversation Read and Write via message tRPC RouterEPSS 0.5%CVE-2026-85624HIGHBlinko 1.8.7 Cross-User Private Note Disclosure via noteReferenceListEPSS 0.4%CVE-2026-23481MEDIUMBlinko: Authenticated Arbitrary File Write - saveAdditionalDevFileEPSS 0.4%CVE-2026-23882HIGHBlinko: Admin RCE - MCP Server Command InjectionEPSS 0.4%CVE-2026-23480MEDIUMBlinko: Low Privilege User Privilege Escalation - upsertUser EndpointEPSS 0.3%CVE-2026-23484MEDIUMBlinko: Authenticated Arbitrary File Write - saveDevPluginEPSS 0.3%CVE-2026-23488MEDIUMBlinko: multiple interfaces in the comment feature allow unauthorized accessEPSS 0.3%CVE-2026-23485MEDIUMBlinko: Unauthorized Path Traversal File Enumeration - music-metadataEPSS 0.3%CVE-2026-23487MEDIUMBlinko: IDOR - user.detail Endpoint Leaks Superadmin TokenEPSS 0.2%