A vulnerability described as problematic has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting.

This vulnerability is known as CVE-2025-9430. It is possible to launch the attack remotely. Furthermore, an exploit is available.