Перейти к содержимому
Noroxi

Записи Bludit

42 опубликованных записей вендора bludit.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 2,4 %
Pre-auth RCE
1
С записью об исправлении
4,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

42 записей
  • CVE-2019-16113
    58В плане

    Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and th

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %

    bludit · bludit8 сент. 2019 г.

  • CVE-2019-17240
    51В плане

    bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-

    КритическаяCVSS 9,8Proof of conceptEPSS 40 %

    bludit · bludit6 окт. 2019 г.

  • CVE-2018-1000811
    49В плане

    bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can res

    ВысокаяCVSS 8,8Proof of conceptEPSS 48 %

    bludit · bludit20 дек. 2018 г.

  • CVE-2020-18879
    40В плане

    Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component '

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    bludit · bludit20 авг. 2021 г.

  • CVE-2020-18190
    37Наблюдать

    Bludit v3.8.1 is affected by directory traversal.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    bludit · bludit2 окт. 2020 г.

  • CVE-2019-12548
    36Наблюдать

    Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/aj

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    bludit · bludit3 июн. 2019 г.

  • CVE-2020-20495
    36Наблюдать

    bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.

    КритическаяCVSS 9,1Эксплойта нетEPSS 2 %

    bludit · bludit31 авг. 2021 г.

  • CVE-2026-25099
    35Наблюдать

    Remote Code Execution via Unrestricted File Upload in Bludit

    ВысокаяCVSS 8,7Proof of conceptEPSS 2 %

    bludit · bludit27 мар. 2026 г.

  • CVE-2019-12742
    35Наблюдать

    Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bludit · bludit5 июн. 2019 г.

  • CVE-2020-20210
    35Наблюдать

    Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bludit · bludit26 июн. 2023 г.

  • CVE-2023-31572
    35Наблюдать

    An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requ

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bludit · bludit16 мая 2023 г.

  • CVE-2024-24551
    35Наблюдать

    Bludit - Remote Code Execution (RCE) through Image API

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    bludit · bludit24 июн. 2024 г.

  • CVE-2024-24550
    35Наблюдать

    Bludit - Remote Code Execution (RCE) through File API

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    bludit · bludit24 июн. 2024 г.

  • CVE-2021-25808
    31Наблюдать

    A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    bludit · bludit23 июл. 2021 г.

  • CVE-2023-24674
    31Наблюдать

    Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    bludit · bludit1 сент. 2023 г.

  • CVE-2020-19228
    28Наблюдать

    An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    bludit · bludit11 мая 2022 г.

  • CVE-2020-23765
    28Наблюдать

    A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    bludit · bludit21 мая 2021 г.

  • CVE-2023-53907
    28Наблюдать

    Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin

    ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %

    bludit · bludit17 дек. 2025 г.

  • CVE-2021-35323
    26Наблюдать

    Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

    СредняяCVSS 6,1Proof of conceptEPSS 6 %

    bludit · bludit19 окт. 2021 г.

  • CVE-2018-16313
    24Наблюдать

    Bludit 2.3.4 allows XSS via a user name.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    bludit · bludit1 сент. 2018 г.

  • CVE-2024-24554
    24Наблюдать

    Bludit - Insecure Token Generation

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    bludit · bludit24 июн. 2024 г.

  • CVE-2024-24553
    23Наблюдать

    Bludit uses SHA1 as Password Hashing Algorithm

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    bludit · bludit24 июн. 2024 г.

  • CVE-2023-31698
    22Наблюдать

    Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.

    СредняяCVSS 5,4Proof of conceptEPSS 3 %

    bludit · bludit17 мая 2023 г.

  • CVE-2024-24552
    22Наблюдать

    Bludit is Vulnerable to Session Fixation

    СредняяCVSS 5,7Эксплойта нетEPSS 0 %

    bludit · bludit24 июн. 2024 г.

  • CVE-2021-45744
    21Наблюдать

    A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    bludit · bludit6 янв. 2022 г.