Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/Bludit CMS

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Bludit CMS versions up to 3.22.0 and 4.0.0-beta-1 contain an authorization bypass vulnerability. Authenticated users with the Author role can enumerate and delete media files belonging to other users, including administrators, by exploiting unprotected AJAX endpoints. This bypasses the intended IMAGE_RESTRICT isolation control, allowing unauthorized access and deletion of media files across user pages.

Join the discussion

Bludit CMS versions up to 3.22.0 and 4.0.0-beta-1 contain a missing authorization vulnerability that allows authenticated users with Author or Editor roles to access private drafts and scheduled posts of any user, including administrators. This occurs via the content-get-list AJAX endpoint, which does not enforce ownership constraints when the draft parameter is set to true. The vulnerability exposes pre-publication content and sensitive notes site-wide.

Join the discussion

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save request. Attackers can submit reserved fields such as type and username through the Pages::edit() function in bl-kernel/pages.class.php, which iterates all fields declared in dbFields without per-field authorization, enabling an Author to convert pages to static site-wide navigation entries or transfer page ownership to arbitrary accounts.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/Bludit CMS
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses