
CVE-2026-25614 Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. https://www.cve.org/CVERecord?id=CVE-2026-25614
Post summary
Blesta versions 3.x to 5.x before 5.13.3 are vulnerable to object injection (CVE-2026-25614), as noted in the CVE record.

