Stored Cross-Site Scripting Vulnerability in Bludit Image Upload Feature
CVE-2026-25100
4.8MEDIUM
What is CVE-2026-25100?
Bludit is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in its image upload functionality. An authenticated user with content upload rights—such as roles of Author, Editor, or Administrator—can upload an SVG file containing malicious code, which is executed when a victim accesses the URL of the uploaded SVG resource. The resulting uploaded content can be accessed by anyone, even without authentication, posing significant security risks. While the vendor was alerted to this issue, communication ceased midway through the remediation process, and all versions leading up to 3.18.2 are known to be vulnerable, with the possibility of future versions also being at risk.
Affected Version(s)
Bludit 0 <= 3.18.2
