CVE-2026-41456
published 2026-04-21CVE-2026-41456: Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject…
PriorityP339medium5.1CVSS 4.0
AVNACLATNPRNUIAVCNVINVANSCLSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EXPLOIT
EPSS
1.24%
67.4th percentile
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bludit | bludit | <= 3.20 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Bludit up to 3.20 URL cross site scripting (6732dde / EUVD-2026-24239)
vuldb·2026-04-21·CVSS 5.1
CVE-2026-41456 [MEDIUM] Bludit up to 3.20 URL cross site scripting (6732dde / EUVD-2026-24239)
A vulnerability identified as problematic has been detected in Bludit up to 3.20. The impacted element is an unknown function of the component URL Handler. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-41456. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-xmmc-cmm8-3rvm: Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers
ghsa_unreviewed·2026-04-21
CVE-2026-41456 [MEDIUM] CWE-79 GHSA-xmmc-cmm8-3rvm: Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.
No detection rules found.
No writeups or analysis indexed.
2026-04-21
Published