V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

44 / 44
Vendor: bludit×Clear all
8.8
CVE-2019-16113CVE
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code…
2019-01-01
EPSS78.0%
pct 99
8.8
CVE-2018-1000811CVE
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability i…
2018-01-01
EPSS47.6%
pct 98
9.8
CVE-2019-17240CVE
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protectio…
2019-01-01Pre-auth
EPSS39.6%
pct 98
6.1
CVE-2021-35323CVE
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/logi…
2021-01-01Pre-auth
EPSS5.6%
pct 91
9.8
CVE-2020-18879CVE
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by …
2020-01-01Pre-auth
EPSS3.1%
pct 86
8.8
CVE-2019-12548CVE
Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php f…
2019-01-01
EPSS3.0%
pct 85
5.4
CVE-2023-31698CVE
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NO…
2023-01-01
EPSS2.6%
pct 83
9.1
CVE-2020-18190CVE
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary…
2020-01-01Pre-auth
EPSS1.9%
pct 77
8.7
CVE-2026-25099CVE
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of …
2026-01-01
EPSS1.9%
pct 77
9.1
CVE-2020-20495CVE
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `…
2020-01-01Pre-auth
EPSS1.5%
pct 70
5.4
CVE-2021-45745CVE
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin …
2021-01-01
EPSS1.4%
pct 69
5.4
CVE-2021-45744CVE
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section …
2021-01-01
EPSS1.4%
pct 69
8.8
CVE-2019-12742CVE
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account, inclu…
2019-01-01
EPSS1.3%
pct 66
4.9
CVE-2020-15026CVE
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal appro…
2020-01-01
EPSS1.3%
pct 66
7.8
CVE-2021-25808CVE
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execut…
2021-01-01
EPSS1.2%
pct 64
7.2
CVE-2020-19228CVE
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attacke…
2020-01-01
EPSS1.2%
pct 64
7.2
CVE-2020-23765CVE
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bl…
2020-01-01
EPSS1.1%
pct 61
8.8
CVE-2020-20210CVE
Bludit 3.9.2 is vulnerable to Remote Code Execution (RCE) via /admin/ajax/upload-images.
2020-01-01
EPSS1.0%
pct 59
5.4
CVE-2020-13889CVE
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
2020-01-01
EPSS0.9%
pct 53
8.8
CVE-2023-31572CVE
An issue in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator passwo…
2023-01-01
EPSS0.8%
pct 53
5.4
CVE-2023-34845CVE
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the componen…
2023-01-01
EPSS0.8%
pct 51
8.9
CVE-2024-24551CVE
A security vulnerability has been identified in Bludit, allowing authenticated attackers to exe…
2024-01-01
EPSS0.8%
pct 50
6.1
CVE-2018-16313CVE
Bludit 2.3.4 allows XSS via a user name.
2018-01-01Pre-auth
EPSS0.7%
pct 48
8.9
CVE-2024-24550CVE
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of th…
2024-01-01
EPSS0.7%
pct 47
7.1
CVE-2023-53907CVE
Bludit versions before 3.13.1 contain an authenticated file download vulnerability in the Backu…
2023-01-01
EPSS0.7%
pct 47
4.8
CVE-2019-16334CVE
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category…
2019-01-01
EPSS0.7%
pct 47
5.4
CVE-2022-1590CVE
A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerabi…
2022-01-01
EPSS0.6%
pct 45
5.4
CVE-2017-16636CVE
In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and…
2017-01-01
EPSS0.6%
pct 44
5.4
CVE-2020-8812CVE
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG edito…
2020-01-01
EPSS0.6%
pct 44
4.8
CVE-2024-25297CVE
Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to…
2024-01-01
EPSS0.6%
pct 42
4.3
CVE-2020-8811CVE
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other use…
2020-01-01
EPSS0.5%
pct 41
5.4
CVE-2020-15006CVE
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-u…
2020-01-01
EPSS0.5%
pct 39
4.8
CVE-2023-24675CVE
Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary …
2023-01-01
EPSS0.5%
pct 37
5.6
CVE-2024-24552CVE
A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentica…
2024-01-01
EPSS0.4%
pct 30
4.8
CVE-2026-25101CVE
Bludit allows user's session identifier to be set before authentication. The value of this sess…
2026-01-01
EPSS0.4%
pct 27
8.8
CVE-2026-46656ANC
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control fl…
2026-01-01
EPSS0.3%
pct 20
7.1
CVE-2026-46657ANC
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the use…
2026-01-01
EPSS0.3%
pct 18
6.0
CVE-2024-24554CVE
Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensi…
2024-01-01
EPSS0.2%
pct 15
7.8
CVE-2023-24674CVE
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privil…
2023-01-01
EPSS0.2%
pct 14
5.9
CVE-2024-24553CVE
Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could deter…
2024-01-01
EPSS0.2%
pct 12
Select a vulnerability on the left to open the preview.