Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bludit

First CVE: Nov 6, 2017Active for: 9 yearsTotal CVEs: 43
57.3
VTI Score
TOP TARGET

Bludit is a lightweight open-source flat-file content-management system with a notably concentrated vulnerability footprint spanning a single primary product, yet occupies a meaningful position among web-application security concerns. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity and a pattern of acquiring public exploit code, reflecting the system's role as an internet-facing web platform. Recurring weakness classes—including cross-site scripting, unrestricted file uploads, path traversal, deserialization of untrusted data, and command injection—characterize the exposure and point to deficiencies in input sanitization, file handling, and privilege isolation typical of self-hosted content systems. Defenders deploying Bludit should treat its advisories with high priority, inventory instances carefully, and apply patches promptly given the access-control and code-execution implications of the recurrent weakness patterns. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bludit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 6, 2017
8 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16113HIGH
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP cod
Sep 8, 20198.885NOYES
CVE-2018-1000811HIGH
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This at
Dec 20, 20188.864NOYES
CVE-2019-17240CRITICAL
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Oct 6, 20199.863NOYES
CVE-2021-35323MEDIUM
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
Oct 19, 20216.140NOYES
CVE-2026-25099HIGH
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Re
Mar 27, 20268.839NOYES
CVE-2020-18879CRITICAL
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
Aug 20, 20219.832NONO
CVE-2026-25101CRITICAL
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix
Mar 27, 20269.831NONO
CVE-2023-31698MEDIUM
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to in
May 17, 20235.429NOYES
CVE-2020-20495CRITICAL
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
Sep 1, 20219.129NONO
CVE-2020-18190CRITICAL
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.
Oct 2, 20209.128NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
51%
37%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.7%)
Network41 (95.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low42 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None22 (51.2%)
Unknown0 (0.0%)
Required20 (46.5%)
Privileges Required
Low23 (53.5%)
High6 (14.0%)
None14 (32.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.3% of CVEs· 97th percentile
Nuclei
1 CVE
2.3% of CVEs· 95th percentile
ExploitDB
6 CVEs
14.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bludit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bludit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bludit's Products

View all 5 CNAs →

Top CWEs