Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilityidentity-authentication-vulnerabilitywidely-deployed-product-advisory

Multiple Bludit CMS Flaws Enable RCE, XSS, and Session Hijacking

Updated 3mo agoFirst seen Mar 27, 20262 sources

CERT Polska disclosed four vulnerabilities in the Bludit content management system, including an unrestricted file upload flaw tracked as CVE-2026-25099 that can lead to remote code execution, a stored XSS issue in image upload handling (CVE-2026-25100), a session fixation weakness that can enable session hijacking (CVE-2026-25101), and a separate stored XSS flaw in page creation tracked as CVE-2026-4420. The vulnerabilities were reported by researchers Arkadiusz Marta and Yassin Abdelrazek and affect multiple Bludit versions, with CVE-2026-25099 impacting all releases before 3.18.4, CVE-2026-25101 affecting versions before 3.17.2, CVE-2026-25100 affecting all versions through 3.18.2, and CVE-2026-4420 confirmed in 3.17.2 and 3.18.0.

The XSS flaws can be exploited by authenticated users with content or page creation privileges by injecting malicious JavaScript into uploaded SVG content or article tags, with payloads executing when victims access publicly reachable resources without authentication. CERT Polska said the page-creation XSS could be used to automatically create a new site administrator if the victim has sufficient privileges, while the file upload issue could allow direct server-side compromise through remote code execution. The agency also said vendor coordination was incomplete, noting the vendor stopped responding or did not provide details on remediation and affected version ranges, raising uncertainty over whether some future releases may remain vulnerable.

Share:
Multiple Bludit CMS Flaws Enable RCE, XSS, and Session Hijacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Apr 1, 20263mo ago

CERT Polska discloses Bludit stored XSS flaw CVE-2026-4420

CERT Polska publicly disclosed CVE-2026-4420, a stored XSS vulnerability affecting confirmed Bludit versions 3.17.2 and 3.18.0. It noted the vendor did not respond with details about the vulnerability or affected version range during coordination.

Researcher reports CVE-2026-4420 in Bludit to CERT Polska

Researcher Yassin Abdelrazek responsibly reported a stored cross-site scripting vulnerability in Bludit's page creation functionality to CERT Polska. The flaw allowed an authenticated user with page creation privileges to inject JavaScript via the tags field and potentially create a new administrator if a privileged victim triggered it.

Mar 1, 20264mo ago

CERT Polska discloses three Bludit vulnerabilities

CERT Polska publicly disclosed CVE-2026-25099, CVE-2026-25100, and CVE-2026-25101 affecting Bludit. It said CVE-2026-25100 affected all versions through 3.18.2 and warned future versions might remain vulnerable because the vendor stopped responding during coordination.

Bludit fixes CVE-2026-25099 in version 3.18.4

Bludit version 3.18.4 fixed CVE-2026-25099, an unrestricted file upload flaw that could lead to remote code execution and affected versions before 3.18.4. CERT Polska disclosed the issue after coordination.

Bludit fixes CVE-2026-25101 in version 3.17.2

Bludit version 3.17.2 fixed CVE-2026-25101, a session fixation vulnerability affecting versions before 3.17.2. CERT Polska later identified this as one of the coordinatedly disclosed issues.

Researcher reports three Bludit vulnerabilities to CERT Polska

Researcher Arkadiusz Marta responsibly reported three vulnerabilities in the Bludit CMS to CERT Polska, initiating coordinated disclosure. The issues included unrestricted file upload leading to remote code execution, stored XSS in image upload handling, and session fixation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.