📦 Bludit

by Bludit

🔍 What is Bludit?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-20495

CRITICAL CVSS 9.1 Sep 1, 2021

CVE-2020-20495 is an arbitrary file deletion vulnerability in Bludit CMS v3.13.0's backup plugin. Attackers can delete any file on the server by manipulating the 'deleteBackup' parameter. This affects...

CVE-2020-18879

CRITICAL CVSS 9.8 Aug 20, 2021

CVE-2020-18879 is an unrestricted file upload vulnerability in Bludit CMS v3.8.1 that allows remote attackers to upload malicious files via the upload-logo.php component. This can lead to arbitrary co...

CVE-2024-24554

HIGH CVSS 8.2 Jun 24, 2024

This vulnerability in Bludit allows attackers to bypass authentication by predicting sensitive tokens generated using weak MD5 hashing with predictable methods. Attackers can authenticate against the ...

CVE-2024-24552

HIGH CVSS 8.8 Jun 24, 2024

CVE-2024-24552 is a session fixation vulnerability in Bludit CMS that allows attackers to hijack user sessions by tricking victims into using attacker-controlled session IDs. This affects all Bludit u...

CVE-2024-24550

HIGH CVSS 8.1 Jun 24, 2024

This vulnerability in Bludit allows attackers with API token access to upload arbitrary files, including PHP files, leading to remote code execution on the server. It affects Bludit installations with...

CVE-2023-24674

HIGH CVSS 7.8 Sep 1, 2023

CVE-2023-24674 is a privilege escalation vulnerability in Bludit CMS v4.0.0 that allows local attackers to gain administrative privileges by manipulating the role:admin parameter. This affects any Blu...

CVE-2023-31572

HIGH CVSS 8.8 May 16, 2023

This vulnerability in Bludit 4.0.0-rc-2 allows authenticated attackers to change the Administrator password and escalate privileges via a crafted request. It affects any system running the vulnerable ...

CVE-2026-27741

MEDIUM CVSS 4.3 Feb 23, 2026

This CSRF vulnerability in Bludit 3.16.1 allows attackers to trick authenticated administrators into unknowingly uninstalling plugins or installing malicious themes. Attackers can create web pages tha...

CVE-2023-53907

MEDIUM CVSS 6.5 Dec 17, 2025

CVE-2023-53907 is an authenticated file download vulnerability in Bludit's Backup Plugin that allows logged-in users to read arbitrary files through directory traversal. Attackers can exploit this by ...