PT-2026-34045 · Bludit · Bludit
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-41456
CVSS v4.0
5.1
Medium
| AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Bludit CMS versions prior to commit 6732dde
Description
A reflected cross-site scripting issue exists in the search plugin. This allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Malicious scripts can be executed in the browsers of users who visit crafted URLs containing the payload, which may lead to the theft of session cookies or actions performed on behalf of the affected users.
Recommendations
Update to the version containing commit 6732dde.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bludit