VYPR

Bludit

by Bludit

Source repositories

CVEs (48)

  • CVE-2020-23765HigMay 21, 2021
    risk 0.47cvss 7.2epss 0.01

    A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

  • CVE-2021-35323MedOct 19, 2021
    risk 0.43cvss 6.1epss 0.06

    Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

  • CVE-2023-53907MedDec 17, 2025
    risk 0.42cvss 6.5epss 0.01

    Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system…

  • CVE-2018-16313MedSep 1, 2018
    risk 0.40cvss 6.1epss 0.01

    Bludit 2.3.4 allows XSS via a user name.

  • CVE-2026-46657HigJun 8, 2026
    risk 0.39cvss 7.1epss 0.00

    Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to…

  • CVE-2023-31698MedMay 17, 2023
    risk 0.38cvss 5.4epss 0.03

    Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

  • CVE-2026-72576MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the SVG executes in the browser of any user who…

  • CVE-2026-4420MedApr 7, 2026
    risk 0.35cvss 5.4epss 0.00

    Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags field of a newly created…

  • CVE-2026-27742MedFeb 23, 2026
    risk 0.35cvss 5.4epss 0.00

    Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The application performs client-side sanitation of content input but does not enforce equivalent sanitation on the server side. An authenticated user can inject…

  • CVE-2023-34845MedJun 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users…

  • CVE-2021-45745MedJan 6, 2022
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.

  • CVE-2021-45744MedJan 6, 2022
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

  • CVE-2020-15006MedJun 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.

  • CVE-2020-13889MedJun 6, 2020
    risk 0.35cvss 5.4epss 0.01

    showAlert() in the administration panel in Bludit 3.12.0 allows XSS.

  • CVE-2020-8812MedFeb 7, 2020
    risk 0.35cvss 5.4epss 0.01

    Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.

  • CVE-2017-16636MedNov 6, 2017
    risk 0.35cvss 5.4epss 0.01

    In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attackers are able to bypass the basic editor validation to trigger cross site scripting. The XSS is persistent and the request method…

  • CVE-2020-15026MedJun 24, 2020
    risk 0.32cvss 4.9epss 0.01

    Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.

  • CVE-2024-25297MedFeb 17, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

  • CVE-2023-24675MedSep 1, 2023
    risk 0.31cvss 4.8epss 0.00

    Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

  • CVE-2019-16334MedSep 15, 2019
    risk 0.31cvss 4.8epss 0.01

    In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.