CVE-2026-25099

Remote Code Execution via Unrestricted File Upload in Bludit

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.


We have discovered 1,299 live websites that are affected by CVE-2026-25099.

Run a Free Instant Scan




Affected Software

Product  Bludit
Category Content Management System
Vulnerable Domains1,299 live websites (100% of Bludit install base)
Vulnerable Versions
  • from 0 through 3.18.4
Vulnerable Versions Count20 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Mar 27, 2026
  • Updated - Mar 27, 2026

Credits

  • Arkadiusz Marta (finder)

Website Distribution by Country

Number of websites using CVE-2026-25099
United States254 websites



Germany415 websites
Ukraine138 websites
France73 websites
Poland63 websites
Russia58 websites
Switzerland46 websites
Czech Republic24 websites
GB23 websites
Italy19 websites

Website Distribution by TLD

Number of websites using CVE-2026-25099
.de318 websites
.com249 websites
.fr86 websites
.net56 websites
.ru50 websites
.pl47 websites
.org47 websites
.ch44 websites
.eu26 websites
.cz23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25099

Top websites that are affected by CVE-2026-25099. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.de Germany*,***
*******.de Germany*,***
*************.de Germany*,***
*****************.jetzt Germany**,***
************.io United States**,***
********.com United States***,***
*********.com United States***,***
******.de Germany***,***
*****.com United States***,***
************.eu United States***,***
See full domain list

FAQ

CVE-2026-25099 is Unrestricted Upload of File with Dangerous Type in Bludit
A total of 1,299 websites have been identified as vulnerable to CVE-2026-25099, based on global website indexing conducted by WebTechSurvey.
The Bludit is affected by the CVE-2026-25099 vulnerability.
Bludit versions up to 3.18.4 are vulnerable to CVE-2026-25099.
CVE-2026-25099 is resolved in version 3.18.4 of Bludit.