Security Advisory
Blesta 5.13.9 patches one low-severity security issue with defense-in-depth hardening, plus fixes for partial refunds, OAuth2 callbacks, and email blacklists.
Blog · tag
Every post tagged “advisory” — newest first.
Blesta 5.13.9 patches one low-severity security issue with defense-in-depth hardening, plus fixes for partial refunds, OAuth2 callbacks, and email blacklists.
High-impact security advisory for Blesta 3.0.0 through 5.13.7 covering authorization, API code execution, email parsing, and CSRF fixes. Upgrade to 5.13.8 or patch.
Critical security advisory for Blesta 3.0.0 through 5.13.1: input validation and object injection flaws with possible remote code execution. Upgrade to 5.13.3 or patch.
Security advisory: a High-impact path traversal vulnerability affects Blesta 4.0.0 through 5.11.3. Upgrade to 5.11.4 or apply the 5.11.4 or 5.10.4 patch.
Critical security advisory for Blesta 5.0.0 through 5.9.1: a path traversal flaw can chain to account compromise and RCE. Patch or upgrade to 5.9.2 now.
30-day free trial · No credit card · Your server
Everything on this blog ships in the box. Full product, free for 30 days, on your own server.