VendorsPhillips Datablestaall versions
Vulnerabilities

Phillips Data Blesta

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-25614
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5680.
Published 2026-02-03 · Analyzed
7.5EPSS 0.005
CVE-2026-25615
Blesta 3.x through 5.x before 5.13.3 allows object injection, aka CORE-5668.
Published 2026-02-03 · Analyzed
7.2EPSS 0.007
CVE-2024-25859
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.
Published 2024-02-28 · Analyzed
7.1EPSS 0.003
CVE-2026-25616
Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.
Published 2026-02-03 · Analyzed
6.1EPSS 0.004