CVE-2026-25616

MEDIUM NUCLEI

Blesta <5.13.3 - Info Disclosure

Title source: llm

Description

Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.

Nuclei Templates (1)

Blesta <= 5.13.1 - Cross-Site Scripting
MEDIUMVERIFIEDby 0x_Akoko
Shodan: http.title:"Blesta"
FOFA: app="Blesta"

Scores

CVSS v3 4.7
EPSS 0.0246
EPSS Percentile 85.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
phillipsdata/blesta 3.2.0 - 5.13.2
Published Feb 03, 2026
Tracked Since Feb 18, 2026