Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bludit bludit vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-18879
Unrestricted File Upload in Bludit v3.8.1 allows remote malicious users to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Bludit Bludit 3.8.1
7.2
CVSSv3
CVE-2020-19228
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows malicious users to upload arbitrary files.
Bludit Bludit 3.13.0
8.8
CVSSv3
CVE-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
Bludit Bludit 3.9.2
1 EDB exploit
12 Github repositories
9.8
CVSSv3
CVE-2019-17240
bl-kernel/security.class.php in Bludit 3.9.2 allows malicious users to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Bludit Bludit 3.9.2
20 Github repositories
5.4
CVSSv3
CVE-2023-31698
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to insert arbitrary content (users cannot create their own accounts through self-registration).
Bludit Bludit 3.14.1
5.4
CVSSv3
CVE-2023-34845
Bludit v3.14.1 exists to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows malicious users to execute arbitrary web scripts or HTML via uploading a crafted SVG file. NOTE: the product's security model is that users ...
Bludit Bludit 3.14.1
1 Github repository
4.8
CVSSv3
CVE-2019-16334
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.
Bludit Bludit 3.9.2
8.8
CVSSv3
CVE-2023-31572
An issue in Bludit 4.0.0-rc-2 allows authenticated malicious users to change the Administrator password and escalate privileges via a crafted request.
Bludit Bludit 4.0.0
5.4
CVSSv3
CVE-2020-13889
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
Bludit Bludit 3.12.0
3 Github repositories
7.8
CVSSv3
CVE-2021-25808
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows malicious users to execute arbitrary code via a crafted ZIP file.
Bludit Bludit 3.13.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3