Skip to main content
Loading…
    CVE-2026-38329 — Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks — CVE Database · The Intelligence Room