PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-25616

4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.
Description

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
blesta
Updated Sep 18, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

Blesta <= 5.13.1 - Cross-Site Scripting

Blesta 3.x through 5.x before 5.13.3 contains an input validation vulnerability caused by mishandling input, letting attackers potentially exploit the system, exploit requires unspecified conditions. References: https://karmainsecurity.com/KIS-2026-01 https://www.blesta.com/2026/01/28/security-advisory/ https://nvd.nist.gov/vuln/detail/CVE-2026-25616 Remediation: Upgrade to version 5.13.3 or later.

Used 3.3k times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →