Loading market data...
← Back to CVE feed

CVE-2026-25099

UNKNOWN View on NVD ↗

Description

Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension without restriction, which can then be executed, leading to Remote Code Execution. This issue was fixed in 3.18.4.

Published: Mar 27, 2026 12:16 UTC Modified: Mar 27, 2026 12:16 UTC