VYPR

Bludit

by Bludit

Source repositories

CVEs (48)

  • CVE-2026-25100MedMar 27, 2026
    risk 0.28cvss 5.4epss 0.00

    Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, which is executed when a victim…

  • CVE-2026-27741MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative…

  • CVE-2020-8811MedFeb 7, 2020
    risk 0.28cvss 4.3epss 0.01

    ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

  • CVE-2026-41456MedApr 21, 2026
    risk 0.26cvss epss 0.00

    Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of…

  • CVE-2022-1590LowMay 5, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input leads to cross site scripting.…

  • CVE-2019-17240CriOct 6, 2019
    risk 0.06cvss 9.8epss 0.40

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

  • CVE-2019-12742HigJun 5, 2019
    risk 0.00cvss 8.8epss 0.01

    Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter).

  • CVE-2019-12548HigJun 3, 2019
    risk 0.00cvss 8.8epss 0.03

    Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.

Page 3 of 3