Blesta Object Injection Vulnerability Allowing Potential Remote Code Execution

Vulnerability

An object injection vulnerability has been identified in Blesta versions 3.x through 5.x prior to 5.13.3. This vulnerability, referenced as CORE-5680, could potentially allow remote code execution under certain conditions.

Impact

Exploitation of this vulnerability could lead to object injection, with the possibility of remote code execution.

Remediation

Users are advised to upgrade to Blesta version 5.13.3. Instructions for upgrading and patching existing installations are available in the Blesta user manual. For those using an affected unsupported version of Blesta (between 3.0 and 5.10), it is recommended to upgrade as soon as possible.

Added: Feb 3, 2026, 8:17 PM
Updated: Feb 3, 2026, 8:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.8
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.