Stored Cross-Site Scripting Vulnerability in Bludit by Bludit
CVE-2026-4420

5.1MEDIUM

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-4420?

Bludit CMS has a vulnerability in its page creation functionality that allows an authenticated attacker, such as an Author, Editor, or Administrator, to inject malicious JavaScript code through the tags field of a newly created article. This injected script executes when an unsuspecting user visits the affected page, creating a potential for unauthorized actions. Additionally, if the victim's privileges are sufficient, the attack could lead to the automatic elevation of the attacker's account to that of a site administrator. Testing confirmed that versions 3.17.2 and 3.18.0 are affected; however, other versions may also be susceptible. Immediate action is advised to secure impacted sites.

Affected Version(s)

Bludit 3.17.2

Bludit 3.18.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yassin Abdelrazek
.