Junglewise Threat Intelligence

CVE-2026-72576: Bludit stored cross-site scripting in logo upload

CVE-2026-72576 · Severity: medium · CVSS 5.4 · Published 2026-08-10

Technologies: Bludit. Vendors: Bludit.

Executive brief

Bludit is a flat-file content management system used to host and manage websites. An authenticated user with Author privileges can upload a malicious SVG file as the site logo, injecting JavaScript code that executes in the browsers of all site visitors who load the logo. This allows an attacker to steal session cookies, redirect users to phishing sites, or perform actions on behalf of legitimate visitors.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Bludit 4.0.0-beta's logo upload functionality. An authenticated Author-role user can upload a crafted SVG file containing embedded script tags as the site logo. The vulnerability occurs because the application fails to properly sanitize SVG uploads, allowing arbitrary JavaScript to be embedded and executed in the browser context of any user (including administrators) who loads the logo. The attack requires authentication and the Author role, but achieves stored payload persistence. Patches or remediation guidance from the vendor should be checked for availability.

Affected products

  • Bludit Bludit 4.0.0-beta

Timeline

  • 2026-08-10: disclosed: CVE-2026-72576 published on NVD

References

Related threats