Bludit is a lightweight open-source flat-file content-management system with a notably concentrated vulnerability footprint spanning a single primary product, yet occupies a meaningful position among web-application security concerns. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity and a pattern of acquiring public exploit code, reflecting the system's role as an internet-facing web platform. Recurring weakness classes—including cross-site scripting, unrestricted file uploads, path traversal, deserialization of untrusted data, and command injection—characterize the exposure and point to deficiencies in input sanitization, file handling, and privilege isolation typical of self-hosted content systems. Defenders deploying Bludit should treat its advisories with high priority, inventory instances carefully, and apply patches promptly given the access-control and code-execution implications of the recurrent weakness patterns. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bludit over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16113HIGH Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP cod | Sep 8, 2019 | 8.8 | 85 | NO | YES |
CVE-2018-1000811HIGH bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This at | Dec 20, 2018 | 8.8 | 64 | NO | YES |
CVE-2019-17240CRITICAL bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers. | Oct 6, 2019 | 9.8 | 63 | NO | YES |
CVE-2021-35323MEDIUM Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login. | Oct 19, 2021 | 6.1 | 40 | NO | YES |
CVE-2026-25099HIGH Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Re | Mar 27, 2026 | 8.8 | 39 | NO | YES |
CVE-2020-18879CRITICAL Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'. | Aug 20, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-25101CRITICAL Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix | Mar 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2023-31698MEDIUM Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's security model is that users are trusted by the administrator to in | May 17, 2023 | 5.4 | 29 | NO | YES |
CVE-2020-20495CRITICAL bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter. | Sep 1, 2021 | 9.1 | 29 | NO | NO |
CVE-2020-18190CRITICAL Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture. | Oct 2, 2020 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bludit.
Media articles that mention a CVE ID that affects a product developed by Bludit — matched by CVE ID, not by vendor name.