NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-41456
Summary

Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers to inject arbitrary JavaScript by crafting a malicious search query. Attackers can execute malicious scripts in the browsers of users who visit crafted URLs containing the payload, potentially stealing session cookies or performing actions on behalf of affected users.

Publication Date April 22, 2026, 4:16 a.m.
Registration Date April 25, 2026, 4:03 a.m.
Last Update April 23, 2026, 6:20 a.m.
Related information, measures and tools
Common Vulnerabilities List