Flatpress / Flatpress
36 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-56785 | FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields | HIGH | 8.4 | Jun 23, 2026 |
| CVE-2025-44108 | A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacke… | MEDIUM | 4.8 | May 19, 2025 |
| CVE-2025-29602 | flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories. | MEDIUM | 6.1 | May 7, 2025 |
| CVE-2024-4023 | Stored XSS in flatpressblog/flatpress | HIGH | 8.1 | Mar 20, 2025 |
| CVE-2024-9699 | Cross-Site Scripting (XSS) in flatpressblog/flatpress | MEDIUM | 5.4 | Mar 20, 2025 |
| CVE-2024-9847 | Cross-Site Request Forgery (CSRF) in flatpressblog/flatpress | HIGH | 8.0 | Mar 20, 2025 |
| CVE-2025-25460 | A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated att… | MEDIUM | 4.8 | Feb 24, 2025 |
| CVE-2024-41290 | FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component. | HIGH | 8.1 | Oct 2, 2024 |
| CVE-2024-33210 | A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pag… | MEDIUM | 5.4 | Oct 2, 2024 |
| CVE-2024-33209 | FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows the… | MEDIUM | 5.4 | Oct 2, 2024 |
| CVE-2024-31835 | Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name pa… | MEDIUM | 4.8 | Oct 1, 2024 |
| CVE-2024-25412 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… | MEDIUM | 6.1 | Sep 27, 2024 |
| CVE-2024-25411 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… | MEDIUM | 6.1 | Sep 27, 2024 |
| CVE-2023-1148 | Cross-site Scripting (XSS) - Stored in flatpressblog/flatpress | MEDIUM | 4.8 | Mar 2, 2023 |
| CVE-2023-1147 | Cross-site Scripting (XSS) - Stored in flatpressblog/flatpress | MEDIUM | 5.4 | Mar 2, 2023 |
| CVE-2023-1146 | Cross-site Scripting (XSS) - Generic in flatpressblog/flatpress | MEDIUM | 5.4 | Mar 2, 2023 |
| CVE-2023-1107 | Cross-site Scripting (XSS) - Stored in flatpressblog/flatpress | MEDIUM | 5.4 | Mar 2, 2023 |
| CVE-2023-1106 | Cross-site Scripting (XSS) - Reflected in flatpressblog/flatpress | MEDIUM | 6.1 | Mar 2, 2023 |
| CVE-2023-1105 | External Control of File Name or Path in flatpressblog/flatpress | HIGH | 8.1 | Mar 1, 2023 |
| CVE-2023-1104 | Cross-site Scripting (XSS) - Stored in flatpressblog/flatpress | MEDIUM | 5.4 | Mar 1, 2023 |
| CVE-2023-0947 | Path Traversal in flatpressblog/flatpress | CRITICAL | 9.8 | Feb 22, 2023 |
| CVE-2022-4822 | FlatPress Setup main.lib.php cross site scripting | MEDIUM | 6.1 | Dec 28, 2022 |
| CVE-2022-4821 | FlatPress XML File Handler/MD File admin.uploader.php onupload cross site scripting | MEDIUM | 6.1 | Dec 28, 2022 |
| CVE-2022-4820 | FlatPress Admin Area admin.entry.list.php cross site scripting | MEDIUM | 6.1 | Dec 28, 2022 |
| CVE-2022-4755 | FlatPress Media Manager Plugin panel.mediamanager.file.php main cross site scripting | MEDIUM | 6.1 | Dec 27, 2022 |
Showing 1 to 25 of 36 CVEs