CVE-2026-41456: Bludit CMS Reflected XSS via Search Plugin
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41456?
CVE-2026-41456 has a medium severity level due to its impact allowing untrusted JavaScript execution.
How do I fix CVE-2026-41456?
To fix CVE-2026-41456, update to Bludit CMS version after commit 6732dde.
Who is affected by CVE-2026-41456?
CVE-2026-41456 affects all versions of Bludit CMS prior to commit 6732dde.
What type of vulnerability is CVE-2026-41456?
CVE-2026-41456 is a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2026-41456 be exploited remotely?
Yes, CVE-2026-41456 can be exploited remotely by unauthenticated attackers through a crafted search query.