Loading product vulnerabilities…
Total
4
Critical
0
High
3
Medium
1
CISA KEV
0
Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.