Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.
We have discovered 1,299 live websites that are affected by CVE-2026-25099.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 1,299 live websites (100% of Bludit install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 20 versions ( 91% of all versions) |
| 254 websites | |
| 415 websites | |
| 138 websites | |
| 73 websites | |
| 63 websites | |
| 58 websites | |
| 46 websites | |
| 24 websites | |
| 23 websites | |
| 19 websites |
| .de | 318 websites |
| .com | 249 websites |
| .fr | 86 websites |
| .net | 56 websites |
| .ru | 50 websites |
| .pl | 47 websites |
| .org | 47 websites |
| .ch | 44 websites |
| .eu | 26 websites |
| .cz | 23 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.de | *,*** | ||
| *******.de | *,*** | ||
| *************.de | *,*** | ||
| *****************.jetzt | **,*** | ||
| ************.io | **,*** | ||
| ********.com | ***,*** | ||
| *********.com | ***,*** | ||
| ******.de | ***,*** | ||
| *****.com | ***,*** | ||
| ************.eu | ***,*** |
FAQ