Bludit

Bludit

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.22%
  • Veröffentlicht 24.06.2024 07:15:14
  • Zuletzt bearbeitet 02.01.2026 20:31:00

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execut...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 24.06.2024 07:15:13
  • Zuletzt bearbeitet 02.01.2026 20:19:43

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper h...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 17.02.2024 06:15:53
  • Zuletzt bearbeitet 21.11.2024 09:00:35

Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 01.09.2023 10:15:08
  • Zuletzt bearbeitet 21.11.2024 07:48:17

Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 01.09.2023 10:15:07
  • Zuletzt bearbeitet 21.11.2024 07:48:17

Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

Exploit
  • EPSS 1.08%
  • Veröffentlicht 26.06.2023 18:15:09
  • Zuletzt bearbeitet 21.11.2024 05:11:54

Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 16.06.2023 04:15:14
  • Zuletzt bearbeitet 21.11.2024 08:07:37

Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's se...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 17.05.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 08:02:09

Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 16.05.2023 14:15:09
  • Zuletzt bearbeitet 23.01.2025 15:15:08

An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 11.05.2022 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:09:02

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.