CVE-2026-27741

Source
https://cve.org/CVERecord?id=CVE-2026-27741
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27741.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27741
Published
2026-02-23T22:16:25.233Z
Modified
2026-02-28T05:08:39.296858Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

Bludit version 3.16.1 contains a cross-site request forgery (CSRF) vulnerability in the /admin/uninstall-plugin/ and /admin/install-theme/ endpoints. The application does not implement anti-CSRF tokens or other request origin validation mechanisms for these administrative actions. An attacker can induce an authenticated administrator to visit a malicious page that silently submits crafted requests, resulting in unauthorized plugin uninstallation or theme installation. This may lead to loss of functionality, execution of untrusted code via malicious themes, and compromise of system integrity.

References

Affected packages

Git / github.com/bludit/bludit

Affected ranges

Type
GIT
Repo
https://github.com/bludit/bludit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27741.json"