Bludit

Bludit

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.72%
  • Veröffentlicht 15.06.2026 00:00:00
  • Zuletzt bearbeitet 16.06.2026 15:16:42

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

Medienbericht
  • EPSS 0.63%
  • Veröffentlicht 15.06.2026 00:00:00
  • Zuletzt bearbeitet 16.06.2026 15:16:37

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a vali...

  • EPSS 0.27%
  • Veröffentlicht 08.06.2026 15:05:45
  • Zuletzt bearbeitet 09.06.2026 13:57:49

Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tokens. When an administrator disables a user account,...

  • EPSS 0.29%
  • Veröffentlicht 08.06.2026 14:51:32
  • Zuletzt bearbeitet 09.06.2026 13:57:49

Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 21.04.2026 18:03:00
  • Zuletzt bearbeitet 22.04.2026 21:20:25

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious...

  • EPSS 0.16%
  • Veröffentlicht 07.04.2026 10:46:19
  • Zuletzt bearbeitet 20.04.2026 16:51:25

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker with page creation privileges (such as Author, Editor, or Administrator) can embed a malicious JavaScript payload in the tags fiel...

  • EPSS 0.36%
  • Veröffentlicht 27.03.2026 12:16:20
  • Zuletzt bearbeitet 02.04.2026 20:53:39

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. ...

  • EPSS 0.19%
  • Veröffentlicht 27.03.2026 12:16:20
  • Zuletzt bearbeitet 01.04.2026 13:56:52

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, wh...

  • EPSS 1.92%
  • Veröffentlicht 27.03.2026 12:16:19
  • Zuletzt bearbeitet 01.04.2026 14:16:35

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 23.02.2026 22:01:57
  • Zuletzt bearbeitet 26.02.2026 03:03:26

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms fo...