Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown

CVE-2020-18879

Disclosure Date: August 20, 2021 (last updated February 23, 2025)
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Attacker Value
Unknown

CVE-2021-25808

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
Attacker Value
Unknown

CVE-2020-23765

Disclosure Date: May 21, 2021 (last updated February 22, 2025)
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
Attacker Value
Unknown

CVE-2020-18190

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.
Attacker Value
Unknown

CVE-2020-15026

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Bludit 3.12.0 allows admins to use a /plugin-backup-download?file=../ directory traversal approach for arbitrary file download via backup/plugin.php.
Attacker Value
Unknown

CVE-2020-15006

Disclosure Date: June 24, 2020 (last updated February 21, 2025)
Bludit 3.12.0 allows stored XSS via JavaScript code in an SVG document to bl-kernel/ajax/logo-upload.php.
Attacker Value
Unknown

CVE-2020-13889

Disclosure Date: June 06, 2020 (last updated February 21, 2025)
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
Attacker Value
Unknown

CVE-2020-8812

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the WYSIWYG editor. NOTE: the vendor's perspective is that this is "not a bug.
Attacker Value
Unknown

CVE-2020-8811

Disclosure Date: February 07, 2020 (last updated February 21, 2025)
ajax/profile-picture-upload.php in Bludit 3.10.0 allows authenticated users to change other users' profile pictures.
Attacker Value
Unknown

CVE-2019-16334

Disclosure Date: September 15, 2019 (last updated November 27, 2024)
In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: this may overlap CVE-2017-16636.