Bludit / Bludit
45 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-72576 | Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload | MEDIUM | 5.4 | Aug 10, 2026 |
| CVE-2026-46657 | Bludit's persistent authentication tokens not revoked upon account disablement | HIGH | 7.1 | Jun 8, 2026 |
| CVE-2026-46656 | Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions | HIGH | 8.8 | Jun 8, 2026 |
| CVE-2026-41456 | Bludit CMS Reflected XSS via Search Plugin | MEDIUM | 5.1 | Apr 21, 2026 |
| CVE-2026-4420 | Stored XSS via Page Creating functionality in Bludit | MEDIUM | 5.1 | Apr 7, 2026 |
| CVE-2026-25099 | Remote Code Execution via Unrestricted File Upload in Bludit | HIGH | 8.7 | Mar 27, 2026 |
| CVE-2026-25100 | Stored XSS via SVG File Upload in Bludit | MEDIUM | 4.8 | Mar 27, 2026 |
| CVE-2026-25101 | Session Fixation in Bludit | MEDIUM | 4.8 | Mar 27, 2026 |
| CVE-2026-27741 | Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints | MEDIUM | 5.1 | Feb 23, 2026 |
| CVE-2026-27742 | Bludit <= 3.16.2 Stored XSS in Post Content | MEDIUM | 5.1 | Feb 23, 2026 |
| CVE-2023-53907 | Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin | HIGH | 7.1 | Dec 17, 2025 |
| CVE-2024-24554 | Bludit - Insecure Token Generation | MEDIUM | 6.0 | Jun 24, 2024 |
| CVE-2024-24553 | Bludit uses SHA1 as Password Hashing Algorithm | MEDIUM | 5.9 | Jun 24, 2024 |
| CVE-2024-24552 | Bludit is Vulnerable to Session Fixation | MEDIUM | 5.7 | Jun 24, 2024 |
| CVE-2024-24551 | Bludit - Remote Code Execution (RCE) through Image API | HIGH | 8.9 | Jun 24, 2024 |
| CVE-2024-24550 | Bludit - Remote Code Execution (RCE) through File API | HIGH | 8.9 | Jun 24, 2024 |
| CVE-2024-25297 | Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edi… | MEDIUM | 4.8 | Feb 17, 2024 |
| CVE-2023-24675 | Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL. | MEDIUM | 4.8 | Sep 1, 2023 |
| CVE-2023-24674 | Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter. | HIGH | 7.8 | Sep 1, 2023 |
| CVE-2020-20210 | Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images. | HIGH | 8.8 | Jun 26, 2023 |
| CVE-2023-34845 | Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to exe… | MEDIUM | 5.4 | Jun 16, 2023 |
| CVE-2023-31698 | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by th… | MEDIUM | 5.4 | May 17, 2023 |
| CVE-2023-31572 | An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request. | HIGH | 8.8 | May 16, 2023 |
| CVE-2020-19228 | An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files. | HIGH | 7.2 | May 11, 2022 |
| CVE-2022-1590 | Bludit New Content Module new-content cross site scripting | MEDIUM | 5.4 | May 5, 2022 |
Showing 1 to 25 of 45 CVEs