Bludit records
42 published records for vendor bludit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.4%
- Pre-auth RCE
- 1
- With a fix record
- 4.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-434 Unrestricted Upload of File with Dangerous Type8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-384 Session Fixation2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-862 Missing Authorization2
The weakness classes this vendor ships most often: where to look.
CWEAll records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2019-16113Weaponized | Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and thbludit · bludit · CWE-22 | High8.8 | — | 78.0% | Sep 8, 2019 |
51Plan | CVE-2019-17240Proof of concept | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-bludit · bludit · CWE-307 | Critical9.8 | — | 39.6% | Oct 6, 2019 |
49Plan | CVE-2018-1000811Proof of concept | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can resbludit · bludit · CWE-434 | High8.8 | — | 47.6% | Dec 20, 2018 |
40Plan | CVE-2020-18879No exploit | Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bludit · bludit · CWE-434 | Critical9.8 | — | 3.1% | Aug 20, 2021 |
37Monitor | CVE-2020-18190No exploit | Bludit v3.8.1 is affected by directory traversal.bludit · bludit · CWE-22 | Critical9.1 | — | 2.0% | Oct 2, 2020 |
36Monitor | CVE-2019-12548No exploit | Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajbludit · bludit · CWE-434 | High8.8 | — | 3.0% | Jun 3, 2019 |
36Monitor | CVE-2020-20495No exploit | bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.bludit · bludit | Critical9.1 | — | 1.5% | Aug 31, 2021 |
35Monitor | CVE-2026-25099Proof of concept | Remote Code Execution via Unrestricted File Upload in Bluditbludit · bludit · CWE-434 | High8.7 | — | 1.9% | Mar 27, 2026 |
35Monitor | CVE-2019-12742No exploit | Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.bludit · bludit · CWE-639 | High8.8 | — | 1.3% | Jun 5, 2019 |
35Monitor | CVE-2020-20210No exploit | Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.bludit · bludit · CWE-434 | High8.8 | — | 1.3% | Jun 26, 2023 |
35Monitor | CVE-2023-31572No exploit | An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requbludit · bludit | High8.8 | — | 0.8% | May 16, 2023 |
35Monitor | CVE-2024-24551No exploit | Bludit - Remote Code Execution (RCE) through Image APIbludit · bludit · CWE-77 | High8.9 | — | 0.8% | Jun 24, 2024 |
35Monitor | CVE-2024-24550No exploit | Bludit - Remote Code Execution (RCE) through File APIbludit · bludit · CWE-77 | High8.9 | — | 0.7% | Jun 24, 2024 |
31Monitor | CVE-2021-25808No exploit | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.bludit · bludit · CWE-94 | High7.8 | — | 1.2% | Jul 23, 2021 |
31Monitor | CVE-2023-24674No exploit | Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.bludit · bludit · CWE-862 | High7.8 | — | 0.2% | Sep 1, 2023 |
28Monitor | CVE-2020-19228No exploit | An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.bludit · bludit · CWE-434 | High7.2 | — | 1.2% | May 11, 2022 |
28Monitor | CVE-2020-23765No exploit | A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.bludit · bludit · CWE-434 | High7.2 | — | 1.1% | May 21, 2021 |
28Monitor | CVE-2023-53907No exploit | Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Pluginbludit · bludit · CWE-22 | High7.1 | — | 0.8% | Dec 17, 2025 |
26Monitor | CVE-2021-35323Proof of concept | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.bludit · bludit · CWE-79 | Medium6.1 | — | 5.6% | Oct 19, 2021 |
24Monitor | CVE-2018-16313No exploit | Bludit 2.3.4 allows XSS via a user name.bludit · bludit · CWE-79 | Medium6.1 | — | 0.7% | Sep 1, 2018 |
24Monitor | CVE-2024-24554No exploit | Bludit - Insecure Token Generationbludit · bludit · CWE-287 | Medium6.0 | — | 0.2% | Jun 24, 2024 |
23Monitor | CVE-2024-24553No exploit | Bludit uses SHA1 as Password Hashing Algorithmbludit · bludit · CWE-916 | Medium5.9 | — | 0.2% | Jun 24, 2024 |
22Monitor | CVE-2023-31698Proof of concept | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.bludit · bludit · CWE-79 | Medium5.4 | — | 2.6% | May 17, 2023 |
22Monitor | CVE-2024-24552No exploit | Bludit is Vulnerable to Session Fixationbludit · bludit · CWE-384 | Medium5.7 | — | 0.4% | Jun 24, 2024 |
21Monitor | CVE-2021-45744Proof of concept | A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.bludit · bludit · CWE-79 | Medium5.4 | — | 1.4% | Jan 6, 2022 |
- CVE-2019-1611358Plan
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and th
HighCVSS 8.8WeaponizedEPSS 78%bludit · bluditSep 8, 2019
- CVE-2019-1724051Plan
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-
CriticalCVSS 9.8Proof of conceptEPSS 40%bludit · bluditOct 6, 2019
- CVE-2018-100081149Plan
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can res
HighCVSS 8.8Proof of conceptEPSS 48%bludit · bluditDec 20, 2018
- CVE-2020-1887940Plan
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component '
CriticalCVSS 9.8No exploitEPSS 3%bludit · bluditAug 20, 2021
- CVE-2020-1819037Monitor
Bludit v3.8.1 is affected by directory traversal.
CriticalCVSS 9.1No exploitEPSS 2%bludit · bluditOct 2, 2020
- CVE-2019-1254836Monitor
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/aj
HighCVSS 8.8No exploitEPSS 3%bludit · bluditJun 3, 2019
- CVE-2020-2049536Monitor
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
CriticalCVSS 9.1No exploitEPSS 2%bludit · bluditAug 31, 2021
- CVE-2026-2509935Monitor
Remote Code Execution via Unrestricted File Upload in Bludit
HighCVSS 8.7Proof of conceptEPSS 2%bludit · bluditMar 27, 2026
- CVE-2019-1274235Monitor
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.
HighCVSS 8.8No exploitEPSS 1%bludit · bluditJun 5, 2019
- CVE-2020-2021035Monitor
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
HighCVSS 8.8No exploitEPSS 1%bludit · bluditJun 26, 2023
- CVE-2023-3157235Monitor
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requ
HighCVSS 8.8No exploitEPSS 1%bludit · bluditMay 16, 2023
- CVE-2024-2455135Monitor
Bludit - Remote Code Execution (RCE) through Image API
HighCVSS 8.9No exploitEPSS 1%bludit · bluditJun 24, 2024
- CVE-2024-2455035Monitor
Bludit - Remote Code Execution (RCE) through File API
HighCVSS 8.9No exploitEPSS 1%bludit · bluditJun 24, 2024
- CVE-2021-2580831Monitor
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
HighCVSS 7.8No exploitEPSS 1%bludit · bluditJul 23, 2021
- CVE-2023-2467431Monitor
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
HighCVSS 7.8No exploitEPSS 0%bludit · bluditSep 1, 2023
- CVE-2020-1922828Monitor
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
HighCVSS 7.2No exploitEPSS 1%bludit · bluditMay 11, 2022
- CVE-2020-2376528Monitor
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.
HighCVSS 7.2No exploitEPSS 1%bludit · bluditMay 21, 2021
- CVE-2023-5390728Monitor
Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin
HighCVSS 7.1No exploitEPSS 1%bludit · bluditDec 17, 2025
- CVE-2021-3532326Monitor
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
MediumCVSS 6.1Proof of conceptEPSS 6%bludit · bluditOct 19, 2021
- CVE-2018-1631324Monitor
Bludit 2.3.4 allows XSS via a user name.
MediumCVSS 6.1No exploitEPSS 1%bludit · bluditSep 1, 2018
- CVE-2024-2455424Monitor
Bludit - Insecure Token Generation
MediumCVSS 6.0No exploitEPSS 0%bludit · bluditJun 24, 2024
- CVE-2024-2455323Monitor
Bludit uses SHA1 as Password Hashing Algorithm
MediumCVSS 5.9No exploitEPSS 0%bludit · bluditJun 24, 2024
- CVE-2023-3169822Monitor
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.
MediumCVSS 5.4Proof of conceptEPSS 3%bludit · bluditMay 17, 2023
- CVE-2024-2455222Monitor
Bludit is Vulnerable to Session Fixation
MediumCVSS 5.7No exploitEPSS 0%bludit · bluditJun 24, 2024
- CVE-2021-4574421Monitor
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
MediumCVSS 5.4Proof of conceptEPSS 1%bludit · bluditJan 6, 2022