Security Advisory
Blesta 5.13.9 patches one low-severity security issue with defense-in-depth hardening, plus fixes for partial refunds, OAuth2 callbacks, and email blacklists.
Blog · category
Every post filed under Security — newest first.
Blesta 5.13.9 patches one low-severity security issue with defense-in-depth hardening, plus fixes for partial refunds, OAuth2 callbacks, and email blacklists.
High-impact security advisory for Blesta 3.0.0 through 5.13.7 covering authorization, API code execution, email parsing, and CSRF fixes. Upgrade to 5.13.8 or patch.
Critical security advisory for Blesta 3.0.0 through 5.13.1: input validation and object injection flaws with possible remote code execution. Upgrade to 5.13.3 or patch.
Security advisory: a High-impact path traversal vulnerability affects Blesta 4.0.0 through 5.11.3. Upgrade to 5.11.4 or apply the 5.11.4 or 5.10.4 patch.
Critical security advisory for Blesta 5.0.0 through 5.9.1: a path traversal flaw can chain to account compromise and RCE. Patch or upgrade to 5.9.2 now.
Blesta 4.10.1 security advisory fixes a Moderate XSS flaw in the Order Manager plus one other 4.10.0 bug. Mitigation files are provided for 4.6 through 4.9.
Blesta security advisory rated Low affects versions 3.0.0 through 3.6.1, addressing full path disclosure. Upgrade or patch to 3.6.2 to resolve it.
Security advisory for Blesta 3.0.0 through 3.1.3: a Low TOTP two-factor guessing flaw and a Moderate staff ACL privilege issue. Upgrade to 3.1.4 or 3.2.0.
30-day free trial · No credit card · Your server
Everything on this blog ships in the box. Full product, free for 30 days, on your own server.