Detects Bludit CMS instances before version 3.18.4 with the API plugin enabled. The file upload endpoint (POST /api/files/) has no effective file extension validation — any API token holder can upload PHP webshells and execute arbitrary commands as the web server user. The API plugin is disabled by default but when activated, the token is visible to all admin-panel users and may leak through logs or other vulnerabilities.
Is your app exploitable through CVE-2026-25099?
Scan your domain free