Junglewise Threat Intelligence

CVE-2026-27742: Bludit stored XSS in post content

CVE-2026-27742 · Severity: medium · CVSS 5.4 · Published 2026-02-23

Technologies: Bludit. Vendors: Bludit.

Executive brief

Bludit, a flat-file content management system used for building websites and blogs, is vulnerable to a security flaw in its post creation feature. An authorized user can upload malicious scripts that are saved on the server and then executed in the browsers of other visitors or administrators. This could allow an attacker to steal login sessions, hijack user accounts, or deface website content.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Bludit version 3.16.2 within the post content functionality. The root cause is a failure to implement server-side input validation; while the application performs client-side sanitization, an attacker can bypass this by intercepting the request and injecting arbitrary JavaScript into the 'content' parameter. This malicious payload is stored in the database and executed in the context of any user who views the affected post. An authenticated attacker with permissions to create or edit content can leverage this to perform session hijacking, credential theft, or unauthorized actions on behalf of other users. As of the advisory date, the issue was reported in version 3.16.2 and remains a known risk for versions up to and including that release.

Affected products

  • Bludit Bludit <= 3.16.2

Timeline

  • 2024-08-29: disclosed: Initial issue reported on GitHub by catalin-iovita
  • 2026-02-23: advisory: NVD and VulnCheck published advisory details

References

Related threats