VORANT. Threat Intelligence Sign in Get the full feed

Bludit CMS patches RCE and XSS flaws

medium vulnerability

Three vulnerabilities in Bludit CMS, including an authenticated RCE via file upload, were coordinated for disclosure by CERT Polska.

CERT Polska coordinated the disclosure of three vulnerabilities affecting Bludit, a lightweight flat-file CMS. The most severe, CVE-2026-25099, allows an authenticated attacker holding a valid API token to upload arbitrary file types through Bludit's API plugin, which can then be executed on the server to achieve remote code execution. This was fixed in version 3.18.4.

The second issue, CVE-2026-25100, is a stored cross-site scripting vulnerability in the image upload feature. Users with content-upload privileges (Author, Editor, or Administrator roles) can upload a malicious SVG file that executes JavaScript when a victim views the uploaded resource, which is itself accessible without authentication. Notably, the vendor stopped responding partway through the coordinated disclosure process, and this flaw remains unpatched as of the advisory — all versions up to 3.18.2 are confirmed vulnerable and later versions may also be affected.

The third vulnerability, CVE-2026-25101, is a session fixation flaw where a session identifier assigned before authentication persists unchanged after login, allowing an attacker to pre-set a session ID and later hijack the victim's authenticated session. This was resolved in version 3.17.2. No evidence of active exploitation was reported; the disclosures stem from a responsible vulnerability report credited to researcher Arkadiusz Marta.

Mentioned in this report

Vulnerabilities CVE-2026-25099pocCVE-2026-25100CVE-2026-25101

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-25099

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free