PatchSiren

bludit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Bludit CVE published 2026-06-15

CVE-2026-50869

CVE-2026-50869 is a directory traversal vulnerability in the api/plugin.php component of Bludit v3.19.0. An attacker can exploit this vulnerability by supplying a crafted request, potentially leading to unauthorized access to sensitive files and data.

CRITICAL Bludit CVE published 2026-06-15

CVE-2026-38329

CVE-2026-38329 is a Remote Code Execution (RCE) vulnerability in Bludit CMS before version 3.18.4. The vulnerability is caused by the lack of authorization and file extension validation in the POST /api/files/{key} endpoint in bl-plugins/api/plugin.php. An attacker with a valid API token can upload a malicious PHP script and execute arbitrary code on the server. For more information, see [cve-org](https:/ [truncated]

HIGH bludit CVE published 2026-06-08

CVE-2026-46656

CVE-2026-46656 is a high-severity vulnerability in Bludit, a content management system. Versions prior to 3.22.0 are affected by a Broken Access Control flaw, which allows active sessions to remain valid even after the corresponding user account has been physically deleted from the database. This 'Ghost Session' enables revoked users to maintain full unauthorized access to the system. The vulnerability ha [truncated]

MEDIUM bludit CVE published 2026-04-21

CVE-2026-41456

CVE-2026-41456 is a reflected cross-site scripting vulnerability in the search plugin of Bludit CMS prior to commit 6732dde. This vulnerability allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing [truncated]

MEDIUM Bludit CVE published 2026-02-23

CVE-2026-27742

CVE-2026-27742 is a stored cross-site scripting (XSS) vulnerability in Bludit version 3.16.2. The application performs client-side sanitation of content input but does not enforce equivalent sanitation on the server side. An authenticated user can inject arbitrary JavaScript into the content field of a post, which is stored and later rendered to other users without proper output encoding.

MEDIUM Bludit CVE published 2026-02-23

CVE-2026-27741

CVE-2026-27741 is a cross-site request forgery vulnerability in Bludit 3.16.1. The application lacks anti-CSRF tokens for administrative actions, allowing an attacker to induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This vulnerability can lead to loss of functionality, execution [truncated]