Products: 2
Vulnerabilities: 48
Known Exploited: 0
7
Critical Level Threats
18
High Level Threats
21
Medium Level Threats
1
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-72576
Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload
Last Modified: Aug 10, 2026
Published: Aug 10, 2026
CVE-2026-50869
An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.
Last Modified: Jun 26, 2026
Published: Jun 15, 2026
CVE-2026-38329
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a malicious PHP script and execute arbitrary code on the server.
Last Modified: Jun 26, 2026
Published: Jun 15, 2026
CVE-2026-46657
Bludit's persistent authentication tokens not revoked upon account disablement
Last Modified: Jun 08, 2026
Published: Jun 08, 2026
CVE-2026-46656
Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions
Last Modified: Jun 08, 2026
Published: Jun 08, 2026
Items Per Page
