Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bludit MEDIUM 5.4
CVE-2026-4420

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges…

Mitigation only
Fix from $1,600 2026-04-07
Bludit CRITICAL 9.8
CVE-2026-25101

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behav…

Fix: 3.17.2+
Fix from $2,300 2026-03-27
Bludit MEDIUM 5.4
CVE-2026-25100

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges…

Fix: 3.18.2+
Fix from $1,600 2026-03-27
Bludit HIGH 8.8
CVE-2026-25099

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can …

Fix: 3.18.4+
Fix from $1,950 2026-03-27
Bludit MEDIUM 5.4
CVE-2026-27742

Bludit version 3.16.2 contains a stored cross-site scripting (XSS) vulnerability in the post content functionality. The application performs client-s…

Fix: 3.16.2+
Fix from $1,600 2026-02-23
Bludit MEDIUM 6.5
CVE-2023-53907

Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backup Plugin that allows logged-in users to access arbitra…

Fix: 3.13.1+
Fix from $1,600 2025-12-17
Bludit HIGH 8.2
CVE-2024-24554

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. …

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 7.5
CVE-2024-24553

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due …

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 8.8
CVE-2024-24551

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulner…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 8.8
CVE-2024-24552

A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other u…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 8.1
CVE-2024-24550

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File…

Fix: after 3.15.0
Fix from $1,950 2024-06-24
Bludit HIGH 7.8
CVE-2023-24674

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

No fix yet
Fix from $1,950 2023-09-01
Bludit HIGH 8.8
CVE-2020-20210

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

No fix yet
Fix from $1,950 2023-06-26
Bludit MEDIUM 5.4
CVE-2023-34845

Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attack…

No fix yet
Fix from $1,600 2023-06-16
Bludit MEDIUM 5.4
CVE-2023-31698

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are tru…

No fix yet
Fix from $1,600 2023-05-17
Bludit HIGH 8.8
CVE-2023-31572

An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.

No fix yet
Fix from $1,950 2023-05-16
Bludit HIGH 7.2
CVE-2020-19228

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2022-05-11
Bludit MEDIUM 5.4
CVE-2022-1590

A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the Ne…

No fix yet
Fix from $1,600 2022-05-05
Bludit MEDIUM 5.4
CVE-2021-45744

A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

Fix: after 3.13.1
Fix from $1,600 2022-01-06
Bludit MEDIUM 5.4
CVE-2021-45745

A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.

Fix: after 3.13.1
Fix from $1,600 2022-01-06
Bludit MEDIUM 6.1
CVE-2021-35323EPSS 6%

Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

No fix yet
Fix from $1,600 2021-10-19
Bludit CRITICAL 9.1
CVE-2020-20495

bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

No fix yet
Fix from $2,300 2021-09-01
Bludit CRITICAL 9.8
CVE-2020-18879

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln…

No fix yet
Fix from $2,300 2021-08-20
Bludit HIGH 7.8
CVE-2021-25808

A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

No fix yet
Fix from $1,950 2021-07-23
Bludit HIGH 7.2
CVE-2020-23765

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Ad…

No fix yet
Fix from $1,950 2021-05-21
Bludit CRITICAL 9.1
CVE-2020-18190

Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.

No fix yet
Fix from $2,300 2020-10-02
Bludit MEDIUM 5.4
CVE-2020-15006

Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.

No fix yet
Fix from $1,600 2020-06-24
Bludit MEDIUM 5.4
CVE-2020-13889

showAlert() in the administration panel in Bludit 3.12.0 allows XSS.

No fix yet
Fix from $1,600 2020-06-06
Bludit MEDIUM 5.4
CVE-2020-8812

Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not…

No fix yet
Fix from $1,600 2020-02-07
Bludit CRITICAL 9.8
CVE-2019-17240EPSS 40%

bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded…

Patch available
Fix from $2,300 2019-10-06