Stored XSS Vulnerability in Bludit by Bludit
CVE-2026-72576
5.4MEDIUM
What is CVE-2026-72576?
Bludit 4.0.0-beta is susceptible to a stored cross-site scripting (XSS) vulnerability, where low-privileged authenticated users can exploit the platform by uploading a specially crafted SVG file as the site logo. This malicious SVG can include embedded JavaScript, which executes in the browsers of any users who access the affected site, potentially compromising user sessions and allowing unauthorized actions.
Affected Version(s)
Bludit 4.0.0-beta
