PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2026-41456

5.1
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Description

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.

Attack Vector
Network
Privileges Req.
None
User Interaction
A
bludit
Updated Sep 18, 2026View on NVD →
S4E scanner
mediumWeb Vulnerabilities~10 seconds

Bludit CMS <= 3.20.0 - Cross-Site Scripting

Bludit CMS contains a reflected XSS caused by improper sanitization in the search plugin, letting unauthenticated attackers inject arbitrary JavaScript, exploit requires crafted malicious search query. References: https://github.com/bludit/bludit/commit/6732ddedda8b73ce0a017a1b6adf685100244e01 https://gist.github.com/thepiyushkumarshukla/36b213cdb3c7d603e23fd23605cd681e https://nvd.nist.gov/vuln/detail/CVE-2026-41456 Remediation: Update to the version including commit 6732dde or later.

Used 3 times · domain, subdomain, ipv4

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →