Bludit
This hub aggregates every CVE we track for Bludit, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
46
CVEs tracked
5
Critical
18
High
0
In CISA KEV
Severity distribution
MEDIUM21HIGH18CRITICAL5LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2
3
2
0
2
0
1
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Bludit.
- CVE-2026-72576Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload5.4
- CVE-2026-46657Bludit's persistent authentication tokens not revoked upon account disablement7.1
- CVE-2026-46656Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions8.8
- CVE-2026-41456Bludit CMS Reflected XSS via Search Plugin
- CVE-2026-4420Stored XSS via Page Creating functionality in Bludit5.4
- CVE-2026-25099Remote Code Execution via Unrestricted File Upload in Bludit8.8
- CVE-2026-25100Stored XSS via SVG File Upload in Bludit5.4
- CVE-2026-25101Session Fixation in Bludit9.8
- CVE-2026-27741Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints4.3
- CVE-2026-27742Bludit <= 3.16.2 Stored XSS in Post Content5.4
- CVE-2023-53907Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin6.5
- CVE-2024-24554Bludit - Insecure Token Generation8.2
- CVE-2024-24553Bludit uses SHA1 as Password Hashing Algorithm7.5
- CVE-2024-24552Bludit is Vulnerable to Session Fixation8.8
- CVE-2024-24551Bludit - Remote Code Execution (RCE) through Image API8.8
Product normalization is registry-driven with AI assist and human review. How it works