Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-25614 | Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-25859 | A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code. A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code. NVD description · AI analysis pending | 7.1 | <1% |
| — |