Skip to content
Noroxi

Bludit records

42 published records for vendor bludit.

All records

42 records
  • Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and th

    HighCVSS 8.8WeaponizedEPSS 78%

    bludit · bluditSep 8, 2019

  • bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-

    CriticalCVSS 9.8Proof of conceptEPSS 40%

    bludit · bluditOct 6, 2019

  • bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can res

    HighCVSS 8.8Proof of conceptEPSS 48%

    bludit · bluditDec 20, 2018

  • Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component '

    CriticalCVSS 9.8No exploitEPSS 3%

    bludit · bluditAug 20, 2021

  • Bludit v3.8.1 is affected by directory traversal.

    CriticalCVSS 9.1No exploitEPSS 2%

    bludit · bluditOct 2, 2020

  • Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/aj

    HighCVSS 8.8No exploitEPSS 3%

    bludit · bluditJun 3, 2019

  • bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

    CriticalCVSS 9.1No exploitEPSS 2%

    bludit · bluditAug 31, 2021

  • Remote Code Execution via Unrestricted File Upload in Bludit

    HighCVSS 8.7Proof of conceptEPSS 2%

    bludit · bluditMar 27, 2026

  • Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.

    HighCVSS 8.8No exploitEPSS 1%

    bludit · bluditJun 5, 2019

  • Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

    HighCVSS 8.8No exploitEPSS 1%

    bludit · bluditJun 26, 2023

  • An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requ

    HighCVSS 8.8No exploitEPSS 1%

    bludit · bluditMay 16, 2023

  • Bludit - Remote Code Execution (RCE) through Image API

    HighCVSS 8.9No exploitEPSS 1%

    bludit · bluditJun 24, 2024

  • Bludit - Remote Code Execution (RCE) through File API

    HighCVSS 8.9No exploitEPSS 1%

    bludit · bluditJun 24, 2024

  • A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

    HighCVSS 7.8No exploitEPSS 1%

    bludit · bluditJul 23, 2021

  • Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

    HighCVSS 7.8No exploitEPSS 0%

    bludit · bluditSep 1, 2023

  • An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

    HighCVSS 7.2No exploitEPSS 1%

    bludit · bluditMay 11, 2022

  • A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.

    HighCVSS 7.2No exploitEPSS 1%

    bludit · bluditMay 21, 2021

  • Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin

    HighCVSS 7.1No exploitEPSS 1%

    bludit · bluditDec 17, 2025

  • Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

    MediumCVSS 6.1Proof of conceptEPSS 6%

    bludit · bluditOct 19, 2021

  • Bludit 2.3.4 allows XSS via a user name.

    MediumCVSS 6.1No exploitEPSS 1%

    bludit · bluditSep 1, 2018

  • Bludit - Insecure Token Generation

    MediumCVSS 6.0No exploitEPSS 0%

    bludit · bluditJun 24, 2024

  • Bludit uses SHA1 as Password Hashing Algorithm

    MediumCVSS 5.9No exploitEPSS 0%

    bludit · bluditJun 24, 2024

  • Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

    MediumCVSS 5.4Proof of conceptEPSS 3%

    bludit · bluditMay 17, 2023

  • Bludit is Vulnerable to Session Fixation

    MediumCVSS 5.7No exploitEPSS 0%

    bludit · bluditJun 24, 2024

  • A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

    MediumCVSS 5.4Proof of conceptEPSS 1%

    bludit · bluditJan 6, 2022