Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:LDefault status
unaffected
Any version before 3.18.4
affected
Description
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
Any version before 3.18.4
Credits
Arkadiusz Marta
References
cert.pl/posts/2026/03/CVE-2026-25099
github.com/bludit/bludit/releases/tag/3.18.4