A remote code execution (RCE) vulnerability, CVE-2019-10719, was discovered in BlogEngine 3.3.7 and earlier.

~2–3 hours for a first playthrough (depending on puzzle-solving speed).
~2–3 hours for a first playthrough (depending on puzzle-solving speed).