CVE-2015-6967Exploit(nibbleblog / nibbleblog)

HIGHCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for nibbleblog nibbleblog systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.

7.0/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nibbleblog

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-16); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
nibbleblog

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-16: 1Mentions · 2026-04-23: 1Mentions · 2026-05-28: 1PoC Mentioned / Linked · 2026-04-23: 1Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-05-28: 1Active Exploitation · 2026-04-23: 1Technical Details · 2026-03-16: 1Technical Details · 2026-04-23: 103-1604-2305-28
Signal classification2 categories
Exploit
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-04-231
Exploit1
2026-05-281
Exploit1
Full discourse3 posts
  • Bla_Ze 🔥🔥@KuveY81945
    Exploit

    Pwned Nibbles on HTB CVE-2015-6967 → uploaded a PHP reverse shell via Nibbleblog's My Image plugin → caught shell as nibbler → abused misconfigured sudo on http://monitor.sh → root 🏆 https://labs.hackthebox.com/achievement/machine/3216229/121 #HackTheBoxOndo #HTB #CyberSecurity #EthicalHacking #InfoSec

    Post summary

    A HackTheBox participant exploited CVE‑2015‑6967 by uploading a PHP reverse shell through Nibbleblog's My Image plugin and abusing a misconfigured sudo to gain root, demonstrating a working exploit scenario.

    0002050
    15 followersView on X
  • Alameen@Yungpri93993775
    Exploit

    pwned Nibbles on HTB 🟢 source code leaked /nibbleblog/ → gobuster found admin.php → users.xml exposed the username → admin:nibbles got me in → CVE-2015-6967 + MSF = shell as nibbler ✅ enum always wins. #HackTheBox #Nibbles #OSCP https://t.co/eRxkCAJ3rx

    Post summary

    The user showcases exploiting CVE‑2015‑6967 on Hack The Box using a Metasploit module to achieve a shell, without providing PoC details, patch info, or evidence of widespread exploitation.

    00010145
    82 followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    Disclosure

    5/10 NibbleBlog 4.0.3: CVE-2015-6967. File upload via "My image" plugin doesn't validate extension or MIME type. PHP files go straight through. Activated the plugin: /admin.php?controller=plugins&action=install&plugin=my_image

    Post summary

    The tweet discloses a file‑upload flaw (CVE‑2015‑6967) in NibbleBlog 4.0.3 where PHP files can be uploaded via the "My image" plugin due to missing MIME type and extension checks, and it does not mention a PoC, active exploitation, or a patch.

    1000042
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnibbleblognibbleblog---

Explore more