Stored Cross-Site Scripting Vulnerability in Bludit Image Upload Feature
CVE-2026-25100

4.8MEDIUM

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-25100?

Bludit is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in its image upload functionality. An authenticated user with content upload rights—such as roles of Author, Editor, or Administrator—can upload an SVG file containing malicious code, which is executed when a victim accesses the URL of the uploaded SVG resource. The resulting uploaded content can be accessed by anyone, even without authentication, posing significant security risks. While the vendor was alerted to this issue, communication ceased midway through the remediation process, and all versions leading up to 3.18.2 are known to be vulnerable, with the possibility of future versions also being at risk.

Affected Version(s)

Bludit 0 <= 3.18.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arkadiusz Marta
.