VYPR

Vendor CVEs

Bludit

All CVEs

48 total · sorted by risk
  • CVE-2019-16113HigSep 8, 2019
    risk 0.66cvss 8.8epss 0.78

    Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.

  • CVE-2026-50869CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

  • CVE-2020-18879CriAug 20, 2021
    risk 0.64cvss 9.8epss 0.03

    Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.

  • CVE-2018-1000811HigDec 20, 2018
    risk 0.64cvss 8.8epss 0.48

    bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP…

  • CVE-2020-20495CriSep 1, 2021
    risk 0.59cvss 9.1epss 0.02

    bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

  • CVE-2020-18190CriOct 2, 2020
    risk 0.59cvss 9.1epss 0.02

    Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.

  • CVE-2026-38329CriJun 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a…

  • CVE-2026-25101CriMar 27, 2026
    risk 0.57cvss 9.8epss 0.00

    Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in…

  • CVE-2024-24552HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.00

    A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into authorizing a session ID of their choosing.

  • CVE-2024-24551HigJun 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

  • CVE-2020-20210HigJun 26, 2023
    risk 0.57cvss 8.8epss 0.01

    Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

  • CVE-2023-31572HigMay 16, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.

  • CVE-2026-25099HigMar 27, 2026
    risk 0.53cvss 8.8epss 0.02

    Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

  • CVE-2024-24554HigJun 24, 2024
    risk 0.53cvss 8.2epss 0.00

    Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This allows attackers to authenticate against the Bludit API.

  • CVE-2024-24550HigJun 24, 2024
    risk 0.53cvss 8.1epss 0.01

    A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads,…

  • CVE-2023-24674HigSep 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

  • CVE-2021-25808HigJul 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2026-46656HigJun 8, 2026
    risk 0.50cvss 8.8epss 0.00

    Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain…

  • CVE-2024-24553HigJun 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure…

  • CVE-2020-19228HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

  • CVE-2020-23765HigMay 21, 2021
    risk 0.47cvss 7.2epss 0.01

    A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.

  • CVE-2021-35323MedOct 19, 2021
    risk 0.43cvss 6.1epss 0.06

    Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

  • CVE-2023-53907MedDec 17, 2025
    risk 0.42cvss 6.5epss 0.01

    Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitrary files. Attackers can exploit the plugin's download functionality by manipulating file path parameters to read sensitive system…

  • CVE-2018-16313MedSep 1, 2018
    risk 0.40cvss 6.1epss 0.01

    Bludit 2.3.4 allows XSS via a user name.

  • CVE-2026-46657HigJun 8, 2026
    risk 0.39cvss 7.1epss 0.00

    Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account, the application fails to…

  • CVE-2023-31698MedMay 17, 2023
    risk 0.38cvss 5.4epss 0.03

    Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).

  • CVE-2026-72576MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the SVG executes in the browser of any user who…

  • CVE-2026-4420MedApr 7, 2026
    risk 0.35cvss 5.4epss 0.00

    Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags field of a newly created…

  • CVE-2026-27742MedFeb 23, 2026
    risk 0.35cvss 5.4epss 0.00

    Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The application performs client-side sanitation of content input but does not enforce equivalent sanitation on the server side. An authenticated user can inject…

  • CVE-2023-34845MedJun 16, 2023
    risk 0.35cvss 5.4epss 0.01

    Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users…

  • CVE-2021-45745MedJan 6, 2022
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.

  • CVE-2021-45744MedJan 6, 2022
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

  • CVE-2020-15006MedJun 24, 2020
    risk 0.35cvss 5.4epss 0.01

    Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.

  • CVE-2020-13889MedJun 6, 2020
    risk 0.35cvss 5.4epss 0.01

    showAlert() in the administration panel in Bludit 3.12.0 allows XSS.

  • CVE-2020-8812MedFeb 7, 2020
    risk 0.35cvss 5.4epss 0.01

    Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.

  • CVE-2017-16636MedNov 6, 2017
    risk 0.35cvss 5.4epss 0.01

    In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attackers are able to bypass the basic editor validation to trigger cross site scripting. The XSS is persistent and the request method…

  • CVE-2020-15026MedJun 24, 2020
    risk 0.32cvss 4.9epss 0.01

    Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.

  • CVE-2024-25297MedFeb 17, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

  • CVE-2023-24675MedSep 1, 2023
    risk 0.31cvss 4.8epss 0.00

    Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

  • CVE-2019-16334MedSep 15, 2019
    risk 0.31cvss 4.8epss 0.01

    In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.

  • CVE-2026-25100MedMar 27, 2026
    risk 0.28cvss 5.4epss 0.00

    Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, which is executed when a victim…

  • CVE-2026-27741MedFeb 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative…

  • CVE-2020-8811MedFeb 7, 2020
    risk 0.28cvss 4.3epss 0.01

    ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.

  • CVE-2026-41456MedApr 21, 2026
    risk 0.26cvss epss 0.00

    Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of…

  • CVE-2022-1590LowMay 5, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the New Content module. The manipulation of the argument content with the input leads to cross site scripting.…

  • CVE-2019-17240CriOct 6, 2019
    risk 0.06cvss 9.8epss 0.40

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.

  • CVE-2019-12742HigJun 5, 2019
    risk 0.00cvss 8.8epss 0.01

    Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin. This occurs because of bl-kernel/admin/controllers/user-password.php Insecure Direct Object Reference (a modified username POST parameter).

  • CVE-2019-12548HigJun 3, 2019
    risk 0.00cvss 8.8epss 0.03

    Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajax/upload-logo.