Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Bludit MEDIUM 5.4
CVE-2026-4420

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges…

Mitigation only
Fix from $1,600 2026-04-07
Bludit HIGH 7.8
CVE-2023-24674

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

No fix yet
Fix from $1,950 2023-09-01
Bludit HIGH 8.8
CVE-2020-20210

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

No fix yet
Fix from $1,950 2023-06-26
Bludit MEDIUM 5.4
CVE-2023-34845

Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attack…

No fix yet
Fix from $1,600 2023-06-16
Bludit MEDIUM 5.4
CVE-2023-31698

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are tru…

No fix yet
Fix from $1,600 2023-05-17
Bludit HIGH 8.8
CVE-2023-31572

An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.

No fix yet
Fix from $1,950 2023-05-16
Bludit HIGH 7.2
CVE-2020-19228

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2022-05-11
Bludit MEDIUM 5.4
CVE-2022-1590

A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint /admin/new-content of the Ne…

No fix yet
Fix from $1,600 2022-05-05
Bludit MEDIUM 6.1
CVE-2021-35323EPSS 6%

Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

No fix yet
Fix from $1,600 2021-10-19
Bludit CRITICAL 9.1
CVE-2020-20495

bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

No fix yet
Fix from $2,300 2021-09-01
Bludit CRITICAL 9.8
CVE-2020-18879

Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln…

No fix yet
Fix from $2,300 2021-08-20
Bludit HIGH 7.8
CVE-2021-25808

A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

No fix yet
Fix from $1,950 2021-07-23
Bludit HIGH 7.2
CVE-2020-23765

A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Ad…

No fix yet
Fix from $1,950 2021-05-21
Bludit CRITICAL 9.1
CVE-2020-18190

Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.

No fix yet
Fix from $2,300 2020-10-02
Bludit MEDIUM 5.4
CVE-2020-15006

Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.

No fix yet
Fix from $1,600 2020-06-24
Bludit MEDIUM 5.4
CVE-2020-13889

showAlert() in the administration panel in Bludit 3.12.0 allows XSS.

No fix yet
Fix from $1,600 2020-06-06
Bludit MEDIUM 5.4
CVE-2020-8812

Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not…

No fix yet
Fix from $1,600 2020-02-07
Bludit HIGH 8.8
CVE-2019-16113EPSS 78%

Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this P…

No fix yet
Fix from $1,950 2019-09-08
Bludit HIGH 8.8
CVE-2018-1000811EPSS 48%

bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Re…

No fix yet
Fix from $1,950 2018-12-20
Bludit MEDIUM 6.1
CVE-2018-16313

Bludit 2.3.4 allows XSS via a user name.

No fix yet
Fix from $1,600 2018-09-01
Bludit MEDIUM 5.4
CVE-2017-16636

In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attac…

No fix yet
Fix from $1,600 2017-11-06