Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Bludit — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Bludit, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations for the Bludit content management system, covering various weakness types and security tags. It collects vulnerability records reported over a broad time range, ensuring that both historical and recent security issues are accessible for comprehensive analysis. Users can utilize this resource to track vendor advisories from the Bludit development team, understand the characteristics and impact of specific weakness classes associated with this software, and look up the complete vulnerability history of the product to assess its long-term security posture. The data is structured to facilitate efficient searching and cross-referencing, allowing security researchers, administrators, and developers to identify patterns in reported defects and prioritize remediation efforts based on severity and exploitability. By consolidating these entries, the page serves as a centralized reference point for evaluating the risk landscape surrounding Bludit installations. This approach supports informed decision-making regarding system hardening, patch management, and architectural improvements without requiring external database queries or fragmented document searches. All information presented is derived from verified security reports and official communications, maintaining accuracy and relevance for professional use cases. The aggregation methodology ensures that duplicate entries are resolved and that each vulnerability is contextualized within the broader scope of web application security best practices.

Vendor: unspecified

CVE ID Title CVSS Severity Published
CVE-2026-72576 Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload CWE-79 5.4 Medium 2026-08-10
CVE-2026-46657 Bludit's persistent authentication tokens not revoked upon account disablement CWE-212 7.1 High 2026-06-08
CVE-2026-46656 Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions CWE-285 8.8 High 2026-06-08
CVE-2026-41456 Bludit CMS Reflected XSS via Search Plugin CWE-79 6.1AI Medium AI 2026-04-21
CVE-2026-4420 Stored XSS via Page Creating functionality in Bludit CWE-79 5.4AI Medium AI 2026-04-07
CVE-2026-25099 Remote Code Execution via Unrestricted File Upload in Bludit CWE-434 8.8 - 2026-03-27
CVE-2026-25100 Stored XSS via SVG File Upload in Bludit CWE-79 5.4 - 2026-03-27
CVE-2026-25101 Session Fixation in Bludit CWE-384 9.1 - 2026-03-27
CVE-2026-27741 Bludit <= 3.16.1 CSRF in Plugin and Theme Management Endpoints CWE-352 4.3 Medium 2026-02-23
CVE-2026-27742 Bludit <= 3.16.2 Stored XSS in Post Content CWE-79 5.4 Medium 2026-02-23
CVE-2024-24554 Bludit - Insecure Token Generation CWE-338 9.1AI Critical AI 2024-06-24
CVE-2024-24553 Bludit uses SHA1 as Password Hashing Algorithm CWE-916 9.1AI Critical AI 2024-06-24
CVE-2024-24552 Bludit is Vulnerable to Session Fixation CWE-384 8.8AI High AI 2024-06-24
CVE-2024-24551 Bludit - Remote Code Execution (RCE) through Image API CWE-77 8.8AI High AI 2024-06-24
CVE-2024-24550 Bludit - Remote Code Execution (RCE) through File API CWE-77 9.8AI Critical AI 2024-06-24
CVE-2022-1590 Bludit New Content Module new-content cross site scripting CWE-79 3.5 Low 2022-05-05

All 16 known CVE vulnerabilities affecting Bludit with full Chinese analysis, references, and POCs where available.