CVE-2026-27741

MEDIUM

Bludit 3.16.1 - Cross-Site Request Forgery in Plugin and Theme Management Endpoints

Title source: llm
STIX 2.1

Description

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.

References (2)

Core 2
Core References
Issue Tracking issue-tracking
https://github.com/bludit/bludit/issues/1577

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
bludit/bludit 3.16.1
Published Feb 23, 2026
Tracked Since Feb 23, 2026