ProductThird-party advisory
https://github.com/bludit/bludit CVE-2026-72576
MEDIUM
Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload
Record summary
CVE-2026-72576 has a selected CVSS score of 5.4 (medium).
Description
A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Author role) to inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. A stored script tag in the SVG executes in the browser of any user who loads the logo.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
BluditBrowse Bludit / BluditDefault status: unknown | CVE List | 4.0.0-beta | affected |
References
4Vulnerable FileTechnical description
https://github.com/bludit/bludit/blob/dev/bl-kernel/ajax/logo-upload.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-72576 VendorThird-party advisory
https://www.bludit.com/