CVE-2026-25616 Details
Description
Blesta 3.x through 5.x before 5.13.3 mishandles input validation, aka CORE-5665.
An input validation vulnerability has been identified in Blesta versions 3.x through 5.x prior to 5.13.3. This vulnerability, known as CORE-5665, could potentially allow remote code execution under certain conditions.
Users are advised to upgrade to Blesta version 5.13.3. Instructions for upgrading and patching existing installations are available in the Blesta user manual. If using an unsupported version between 3.0 and 5.10, upgrade to 5.13.3.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://seclists.org/fulldisclosure/2026/Feb/0 | CVE | Mailing ListThird Party Advisory |
| https://www.blesta.com/2026/01/28/security-advisory/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| phillipsdata blesta | >= 3.2.0, < 5.13.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | CVE Modified | CVE |
| Feb 3, 2026 | New CVE Received | [email protected] |