Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16213— Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage

CVSS 3.3 · Low EPSS 0.08% · P0

Possible ATT&CK Techniques 1AI

T1552 · Unsecured Credentials

Affected Version Matrix 20

VendorProductVersion RangeStatus
Fantomas42django-blog-zinnia0.1affected
0.2affected
0.3affected
0.4affected
0.5affected
0.6affected
0.7affected
0.8affected
… +12 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-16213

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cleartext storage
Source: CVE Program / CVE List V5
Vulnerability Description
A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5
Vulnerability Title
Fantomas42 Django Blog Zinnia 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Fantomas42 Django Blog Zinnia是Fantomas42个人开发者开源的一款博客内容管理软件。 Fantomas42 Django Blog Zinnia 0.20及之前版本存在加密问题漏洞,该漏洞源于Protected Entry Password Handler组件中文件zinnia/views/mixins/entry_protection.py的功能问题,导致敏感信息以明文形式存储。以下版本受到影响:0.1版本、0.2版本、0.3版本、0.4版本、0.5版本、0.6版本、0
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Fantomas42django-blog-zinnia 0.1 cpe:2.3:a:fantomas42:django-blog-zinnia:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-16213

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16213

登录查看更多情报信息。

News Coverage for CVE-2026-16213 (1)

Vendor Pages for CVE-2026-16213 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16213

No comments yet


Leave a comment