Vulnerabilities > Bludit > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-02-17 CVE-2024-25297 Cross-site Scripting vulnerability in Bludit 3.15.0
Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php.
network
low complexity
bludit CWE-79
4.8
2023-09-01 CVE-2023-24675 Cross-site Scripting vulnerability in Bludit 3.14.1
Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL.
network
low complexity
bludit CWE-79
4.8
2023-06-16 CVE-2023-34845 Unrestricted Upload of File with Dangerous Type vulnerability in Bludit 3.14.1
Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content.
network
low complexity
bludit CWE-434
5.4
2023-05-17 CVE-2023-31698 Cross-site Scripting vulnerability in Bludit 3.14.1
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo.
network
low complexity
bludit CWE-79
5.4
2022-05-05 CVE-2022-1590 Cross-site Scripting vulnerability in Bludit 3.13.1
A vulnerability was found in Bludit 3.13.1.
network
low complexity
bludit CWE-79
5.4
2022-01-06 CVE-2021-45744 Cross-site Scripting vulnerability in Bludit
A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
network
low complexity
bludit CWE-79
5.4
2022-01-06 CVE-2021-45745 Cross-site Scripting vulnerability in Bludit
A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
network
low complexity
bludit CWE-79
5.4
2021-10-19 CVE-2021-35323 Cross-site Scripting vulnerability in Bludit 3.13.1
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
network
low complexity
bludit CWE-79
6.1
2020-06-24 CVE-2020-15026 Path Traversal vulnerability in Bludit 3.12.0
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
network
low complexity
bludit CWE-22
4.9
2020-06-24 CVE-2020-15006 Cross-site Scripting vulnerability in Bludit 3.12.0
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
network
low complexity
bludit CWE-79
5.4