CVE-2026-25100

Stored XSS via SVG File Upload in Bludit

Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author, Editor, or Administrator) can upload an SVG file containing a malicious payload, which is executed when a victim visits the URL of the uploaded resource. The uploaded resource itself is accessible without authentication. The vendor was notified early about this vulnerability, but stopped responding in the middle of coordination. All versions up to 3.18.2 are considered to be vulnerable, future versions might also be vulnerable.


We have discovered 1,299 live websites that are affected by CVE-2026-25100.

Run a Free Instant Scan




Affected Software

Product  Bludit
Category Content Management System
Vulnerable Domains1,299 live websites (100% of Bludit install base)
Vulnerable Versions
  • from 0 through 3.18.2
Vulnerable Versions Count20 versions ( 91% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Mar 27, 2026
  • Updated - Mar 27, 2026

Credits

  • Arkadiusz Marta (finder)

Website Distribution by Country

Number of websites using CVE-2026-25100
United States254 websites



Germany415 websites
Ukraine138 websites
France73 websites
Poland63 websites
Russia58 websites
Switzerland46 websites
Czech Republic24 websites
GB23 websites
Italy19 websites

Website Distribution by TLD

Number of websites using CVE-2026-25100
.de318 websites
.com249 websites
.fr86 websites
.net56 websites
.ru50 websites
.pl47 websites
.org47 websites
.ch44 websites
.eu26 websites
.cz23 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25100

Top websites that are affected by CVE-2026-25100. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.de Germany*,***
*******.de Germany*,***
*************.de Germany*,***
*****************.jetzt Germany**,***
************.io United States**,***
********.com United States***,***
*********.com United States***,***
******.de Germany***,***
*****.com United States***,***
************.eu United States***,***
See full domain list

FAQ

CVE-2026-25100 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Bludit
A total of 1,299 websites have been identified as vulnerable to CVE-2026-25100, based on global website indexing conducted by WebTechSurvey.
The Bludit is affected by the CVE-2026-25100 vulnerability.
Bludit versions up to and including 3.18.2 are vulnerable to CVE-2026-25100.