
CVE-2026-25100 Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker with content upload privileges (such as Author,… https://www.cve.org/CVERecord?id=CVE-2026-25100
Post summary
The text announces a newly identified stored XSS flaw in Bludit’s image upload feature, noting that authenticated users with upload rights can exploit the vulnerability.
