Junglewise Threat Intelligence

CVE-2026-41456: Bludit CMS reflected XSS in search plugin

CVE-2026-41456 · Severity: info · CVSS 5.1 · Published 2026-04-21

Technologies: Bludit, Bludit CMS. Vendors: Bludit.

Executive brief

Bludit CMS, a popular content management system, contains a security flaw in its search functionality. An attacker can trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions or sensitive information, potentially allowing an attacker to take control of the website if an administrator is targeted.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Bludit CMS versions up to 3.20 within the search plugin. The root cause is the improper neutralization of user-supplied input before it is rendered in the search results page, specifically failing to HTML-escape search terms and URLs. An unauthenticated remote attacker can exploit this by crafting a URL containing a malicious JavaScript payload in the search query parameter. If a victim visits this URL, the script executes in their browser context, potentially allowing for session cookie theft or unauthorized actions. The issue is resolved in commit 6732dde by implementing context-aware HTML escaping using htmlspecialchars.

Affected products

  • Bludit Bludit CMS <= 3.20

Timeline

  • 2026-04-19: patched: Fix submitted via pull request 1691
  • 2026-04-21: disclosed: Vulnerability details and CVE published

References

Related threats