Stored XSS Vulnerability in Bludit by Bludit
CVE-2026-72576

5.4MEDIUM

Key Information:

Vendor

Bludit

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72576?

Bludit 4.0.0-beta is susceptible to a stored cross-site scripting (XSS) vulnerability, where low-privileged authenticated users can exploit the platform by uploading a specially crafted SVG file as the site logo. This malicious SVG can include embedded JavaScript, which executes in the browsers of any users who access the affected site, potentially compromising user sessions and allowing unauthorized actions.

Affected Version(s)

Bludit 4.0.0-beta

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nurmurodov Asadbek
.