Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-4420
Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges…
Bludit
Mitigation only
HIGH 7.8
CVE-2023-24674
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
Bludit
No fix yet
HIGH 8.8
CVE-2020-20210
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
Bludit
No fix yet
MEDIUM 5.4
CVE-2023-34845
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attack…
Bludit
No fix yet
MEDIUM 5.4
CVE-2023-31698
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are tru…
Bludit
No fix yet
HIGH 8.8
CVE-2023-31572
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.
Bludit
No fix yet
HIGH 7.2
CVE-2020-19228
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
Bludit
No fix yet
MEDIUM 5.4
CVE-2022-1590
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the Ne…
Bludit
No fix yet
MEDIUM 6.1
CVE-2021-35323EPSS 6%
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
Bludit
No fix yet
CRITICAL 9.1
CVE-2020-20495
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
Bludit
No fix yet
CRITICAL 9.8
CVE-2020-18879
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln…
Bludit
No fix yet
HIGH 7.8
CVE-2021-25808
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
Bludit
No fix yet
HIGH 7.2
CVE-2020-23765
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Ad…
Bludit
No fix yet
CRITICAL 9.1
CVE-2020-18190
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.
Bludit
No fix yet
MEDIUM 5.4
CVE-2020-15006
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
Bludit
No fix yet
MEDIUM 5.4
CVE-2020-13889
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
Bludit
No fix yet
MEDIUM 5.4
CVE-2020-8812
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not…
Bludit
No fix yet
HIGH 8.8
CVE-2019-16113EPSS 78%
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this P…
Bludit
No fix yet
HIGH 8.8
CVE-2018-1000811EPSS 48%
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Re…
Bludit
No fix yet
MEDIUM 6.1
CVE-2018-16313
Bludit 2.3.4 allows XSS via a user name.
Bludit
No fix yet
MEDIUM 5.4
CVE-2017-16636
In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attac…
Bludit
No fix yet