CVE-2026-41456General

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-09-10: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 1Technical Details · 2026-09-10: 104-2104-2209-10
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
General1
2026-04-221
General1
2026-09-101
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41456 - medium 🚨 Bludit CMS <= 3.20.0 - Cross-Site Scripting > Bludit CMS contains a reflected XSS caused by improper sanitization in the search plu... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41456 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces a medium‑severity XSS vulnerability affecting Bludit CMS versions up to 3.20.0, provides a detection reference, but no patches or exploitation details.

    00032359
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41456 Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitr… https://www.cve.org/CVERecord?id=CVE-2026-41456

    Post summary

    The brief mention identifies a reflected XSS in Bludit CMS’s search plugin but provides no PoC, exploit details, patch information, or evidence of active exploitation.

    00010142
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41456 Reflected Cross-Site Scripting in Bludit CMS Search Plugin Prior to Commit 6732dde https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41456

    Post summary

    The text announces CVE-2026‑41456, identifies it as a reflected XSS in the Bludit CMS Search Plugin before a certain commit, but provides no evidence of PoC, exploit, patch, or active exploitation.

    0000050
    4.0K followersView on X

Explore more