What is CVE-2026-72576?
This is a stored XSS vulnerability in Bludit 4.0.0-beta where a low-privileged 'Author' user can inject arbitrary JavaScript by uploading a crafted SVG file as the site logo. The injected script executes in the browser of any user who loads the logo. Administrators should restrict SVG uploads and apply the security patch.
Azərbaycanca: Bu, Bludit 4.0.0-beta versiyasında saxlanılan XSS zəifliyidir. Aşağı səlahiyyətli 'Author' rolundakı istifadəçi, sayt loqosu kimi xüsusi hazırlanmış SVG fayl yükləyərək, loqonu yükləyən istənilən istifadəçinin brauzerində özbaşına JavaScript kodunu icra edə bilər. Sayt administratorları SVG yükləmələrini məhdudlaşdırmalı və təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ1
How can an Author user perform an XSS attack in Bludit 4.0.0-beta?
This is a stored XSS vulnerability. A low-privileged 'Author' user can inject arbitrary JavaScript by uploading a crafted SVG file as the site logo.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.