# Bludit CMS patches RCE and XSS flaws

Published: 2026-03-27 · Severity: medium
Canonical: https://vorant.io/reports/86f3f4e2-28de-5805-b605-6d2e55604a5d/bludit-cms-patches-rce-and-xss-flaws

> Three vulnerabilities in Bludit CMS, including an authenticated RCE via file upload, were coordinated for disclosure by CERT Polska.

CERT Polska coordinated the disclosure of three vulnerabilities affecting Bludit, a lightweight flat-file CMS. The most severe, CVE-2026-25099, allows an authenticated attacker holding a valid API token to upload arbitrary file types through Bludit's API plugin, which can then be executed on the server to achieve remote code execution. This was fixed in version 3.18.4.

The second issue, CVE-2026-25100, is a stored cross-site scripting vulnerability in the image upload feature. Users with content-upload privileges (Author, Editor, or Administrator roles) can upload a malicious SVG file that executes JavaScript when a victim views the uploaded resource, which is itself accessible without authentication. Notably, the vendor stopped responding partway through the coordinated disclosure process, and this flaw remains unpatched as of the advisory — all versions up to 3.18.2 are confirmed vulnerable and later versions may also be affected.

The third vulnerability, CVE-2026-25101, is a session fixation flaw where a session identifier assigned before authentication persists unchanged after login, allowing an attacker to pre-set a session ID and later hijack the victim's authenticated session. This was resolved in version 3.17.2. No evidence of active exploitation was reported; the disclosures stem from a responsible vulnerability report credited to researcher Arkadiusz Marta.

## Mentioned in this report

- Vulnerabilities: CVE-2026-25099 (poc), CVE-2026-25100, CVE-2026-25101

Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-25099

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/86f3f4e2-28de-5805-b605-6d2e55604a5d/bludit-cms-patches-rce-and-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
