VulnSea

Bludit has 4 CVEs on record between 2022 and 2026. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.0 (medium). Most affected products: Bludit CMS (3), bludit (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.0
Publish → KEV
—
Last 90 days
3 prev 0

Products

  • Bludit CMS 3
  • bludit 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Bludit vulnerabilities

CVEs affecting Bludit, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-93366Medium· 5.4
today

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by suppl…

Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author role to enumerate and delete media files belonging to pages owned by other users, including administrators, by suppl…

▾ SunlitBludit · Bludit CMSvia NVD
CVE-2026-93364Medium· 4.3
today

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

▾ SunlitBludit · Bludit CMSvia NVD
CVE-2026-93365Medium· 6.5
today

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

▾ SunlitBludit · Bludit CMSvia NVD
CVE-2020-19228High· 7.2
4y ago

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

▾ Twilightbludit · bluditEPSS 1.2%via NVD
Bludit vulnerabilities (CVEs) · VulnSea