Vulnerabilities > Bludit > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-17 | CVE-2024-25297 | Cross-site Scripting vulnerability in Bludit 3.15.0 Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code and obtain sensitive information via edit-content.php. | 4.8 |
2023-09-01 | CVE-2023-24675 | Cross-site Scripting vulnerability in Bludit 3.14.1 Cross Site Scripting Vulnerability in BluditCMS v.3.14.1 allows attackers to execute arbitrary code via the Categories Friendly URL. | 4.8 |
2023-06-16 | CVE-2023-34845 | Unrestricted Upload of File with Dangerous Type vulnerability in Bludit 3.14.1 Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. | 5.4 |
2023-05-17 | CVE-2023-31698 | Cross-site Scripting vulnerability in Bludit 3.14.1 Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. | 5.4 |
2022-05-05 | CVE-2022-1590 | Cross-site Scripting vulnerability in Bludit 3.13.1 A vulnerability was found in Bludit 3.13.1. | 5.4 |
2022-01-06 | CVE-2021-45744 | Cross-site Scripting vulnerability in Bludit A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. | 5.4 |
2022-01-06 | CVE-2021-45745 | Cross-site Scripting vulnerability in Bludit A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. | 5.4 |
2021-10-19 | CVE-2021-35323 | Cross-site Scripting vulnerability in Bludit 3.13.1 Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. | 6.1 |
2020-06-24 | CVE-2020-15026 | Path Traversal vulnerability in Bludit 3.12.0 Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php. | 4.9 |
2020-06-24 | CVE-2020-15006 | Cross-site Scripting vulnerability in Bludit 3.12.0 Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php. | 5.4 |