Записи Bludit
42 опубликованных записей вендора bludit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,4 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 4,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-434 Unrestricted Upload of File with Dangerous Type8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-384 Session Fixation2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-862 Missing Authorization2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
42 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2019-16113Готовый эксплойт | Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and thbludit · bludit · CWE-22 | Высокая8,8 | — | 78,0 % | 8 сент. 2019 г. |
51В плане | CVE-2019-17240Proof of concept | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-bludit · bludit · CWE-307 | Критическая9,8 | — | 39,6 % | 6 окт. 2019 г. |
49В плане | CVE-2018-1000811Proof of concept | bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can resbludit · bludit · CWE-434 | Высокая8,8 | — | 47,6 % | 20 дек. 2018 г. |
40В плане | CVE-2020-18879Эксплойта нет | Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bludit · bludit · CWE-434 | Критическая9,8 | — | 3,1 % | 20 авг. 2021 г. |
37Наблюдать | CVE-2020-18190Эксплойта нет | Bludit v3.8.1 is affected by directory traversal.bludit · bludit · CWE-22 | Критическая9,1 | — | 2,0 % | 2 окт. 2020 г. |
36Наблюдать | CVE-2019-12548Эксплойта нет | Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/ajbludit · bludit · CWE-434 | Высокая8,8 | — | 3,0 % | 3 июн. 2019 г. |
36Наблюдать | CVE-2020-20495Эксплойта нет | bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.bludit · bludit | Критическая9,1 | — | 1,5 % | 31 авг. 2021 г. |
35Наблюдать | CVE-2026-25099Proof of concept | Remote Code Execution via Unrestricted File Upload in Bluditbludit · bludit · CWE-434 | Высокая8,7 | — | 1,9 % | 27 мар. 2026 г. |
35Наблюдать | CVE-2019-12742Эксплойта нет | Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.bludit · bludit · CWE-639 | Высокая8,8 | — | 1,3 % | 5 июн. 2019 г. |
35Наблюдать | CVE-2020-20210Эксплойта нет | Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.bludit · bludit · CWE-434 | Высокая8,8 | — | 1,3 % | 26 июн. 2023 г. |
35Наблюдать | CVE-2023-31572Эксплойта нет | An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requbludit · bludit | Высокая8,8 | — | 0,8 % | 16 мая 2023 г. |
35Наблюдать | CVE-2024-24551Эксплойта нет | Bludit - Remote Code Execution (RCE) through Image APIbludit · bludit · CWE-77 | Высокая8,9 | — | 0,8 % | 24 июн. 2024 г. |
35Наблюдать | CVE-2024-24550Эксплойта нет | Bludit - Remote Code Execution (RCE) through File APIbludit · bludit · CWE-77 | Высокая8,9 | — | 0,7 % | 24 июн. 2024 г. |
31Наблюдать | CVE-2021-25808Эксплойта нет | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.bludit · bludit · CWE-94 | Высокая7,8 | — | 1,2 % | 23 июл. 2021 г. |
31Наблюдать | CVE-2023-24674Эксплойта нет | Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.bludit · bludit · CWE-862 | Высокая7,8 | — | 0,2 % | 1 сент. 2023 г. |
28Наблюдать | CVE-2020-19228Эксплойта нет | An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.bludit · bludit · CWE-434 | Высокая7,2 | — | 1,2 % | 11 мая 2022 г. |
28Наблюдать | CVE-2020-23765Эксплойта нет | A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.bludit · bludit · CWE-434 | Высокая7,2 | — | 1,1 % | 21 мая 2021 г. |
28Наблюдать | CVE-2023-53907Эксплойта нет | Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Pluginbludit · bludit · CWE-22 | Высокая7,1 | — | 0,8 % | 17 дек. 2025 г. |
26Наблюдать | CVE-2021-35323Proof of concept | Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.bludit · bludit · CWE-79 | Средняя6,1 | — | 5,6 % | 19 окт. 2021 г. |
24Наблюдать | CVE-2018-16313Эксплойта нет | Bludit 2.3.4 allows XSS via a user name.bludit · bludit · CWE-79 | Средняя6,1 | — | 0,7 % | 1 сент. 2018 г. |
24Наблюдать | CVE-2024-24554Эксплойта нет | Bludit - Insecure Token Generationbludit · bludit · CWE-287 | Средняя6,0 | — | 0,2 % | 24 июн. 2024 г. |
23Наблюдать | CVE-2024-24553Эксплойта нет | Bludit uses SHA1 as Password Hashing Algorithmbludit · bludit · CWE-916 | Средняя5,9 | — | 0,2 % | 24 июн. 2024 г. |
22Наблюдать | CVE-2023-31698Proof of concept | Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.bludit · bludit · CWE-79 | Средняя5,4 | — | 2,6 % | 17 мая 2023 г. |
22Наблюдать | CVE-2024-24552Эксплойта нет | Bludit is Vulnerable to Session Fixationbludit · bludit · CWE-384 | Средняя5,7 | — | 0,4 % | 24 июн. 2024 г. |
21Наблюдать | CVE-2021-45744Proof of concept | A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.bludit · bludit · CWE-79 | Средняя5,4 | — | 1,4 % | 6 янв. 2022 г. |
- CVE-2019-1611358В плане
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and th
ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %bludit · bludit8 сент. 2019 г.
- CVE-2019-1724051В плане
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-
КритическаяCVSS 9,8Proof of conceptEPSS 40 %bludit · bludit6 окт. 2019 г.
- CVE-2018-100081149В плане
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can res
ВысокаяCVSS 8,8Proof of conceptEPSS 48 %bludit · bludit20 дек. 2018 г.
- CVE-2020-1887940В плане
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component '
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %bludit · bludit20 авг. 2021 г.
- CVE-2020-1819037Наблюдать
Bludit v3.8.1 is affected by directory traversal.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bludit · bludit2 окт. 2020 г.
- CVE-2019-1254836Наблюдать
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the logo through /admin/aj
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %bludit · bludit3 июн. 2019 г.
- CVE-2020-2049536Наблюдать
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %bludit · bludit31 авг. 2021 г.
- CVE-2026-2509935Наблюдать
Remote Code Execution via Unrestricted File Upload in Bludit
ВысокаяCVSS 8,7Proof of conceptEPSS 2 %bludit · bludit27 мар. 2026 г.
- CVE-2019-1274235Наблюдать
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, including admin.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bludit · bludit5 июн. 2019 г.
- CVE-2020-2021035Наблюдать
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bludit · bludit26 июн. 2023 г.
- CVE-2023-3157235Наблюдать
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted requ
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bludit · bludit16 мая 2023 г.
- CVE-2024-2455135Наблюдать
Bludit - Remote Code Execution (RCE) through Image API
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %bludit · bludit24 июн. 2024 г.
- CVE-2024-2455035Наблюдать
Bludit - Remote Code Execution (RCE) through File API
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %bludit · bludit24 июн. 2024 г.
- CVE-2021-2580831Наблюдать
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %bludit · bludit23 июл. 2021 г.
- CVE-2023-2467431Наблюдать
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %bludit · bludit1 сент. 2023 г.
- CVE-2020-1922828Наблюдать
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bludit · bludit11 мая 2022 г.
- CVE-2020-2376528Наблюдать
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %bludit · bludit21 мая 2021 г.
- CVE-2023-5390728Наблюдать
Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %bludit · bludit17 дек. 2025 г.
- CVE-2021-3532326Наблюдать
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
СредняяCVSS 6,1Proof of conceptEPSS 6 %bludit · bludit19 окт. 2021 г.
- CVE-2018-1631324Наблюдать
Bludit 2.3.4 allows XSS via a user name.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %bludit · bludit1 сент. 2018 г.
- CVE-2024-2455424Наблюдать
Bludit - Insecure Token Generation
СредняяCVSS 6,0Эксплойта нетEPSS 0 %bludit · bludit24 июн. 2024 г.
- CVE-2024-2455323Наблюдать
Bludit uses SHA1 as Password Hashing Algorithm
СредняяCVSS 5,9Эксплойта нетEPSS 0 %bludit · bludit24 июн. 2024 г.
- CVE-2023-3169822Наблюдать
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.
СредняяCVSS 5,4Proof of conceptEPSS 3 %bludit · bludit17 мая 2023 г.
- CVE-2024-2455222Наблюдать
Bludit is Vulnerable to Session Fixation
СредняяCVSS 5,7Эксплойта нетEPSS 0 %bludit · bludit24 июн. 2024 г.
- CVE-2021-4574421Наблюдать
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
СредняяCVSS 5,4Proof of conceptEPSS 1 %bludit · bludit6 янв. 2022 г.