Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2024-33209

Disclosure Date: October 02, 2024 (last updated October 17, 2024)
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
Attacker Value
Unknown

CVE-2024-31835

Disclosure Date: October 01, 2024 (last updated October 08, 2024)
Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a crafted payload to the file name parameter.
Attacker Value
Unknown

CVE-2024-25412

Disclosure Date: September 27, 2024 (last updated October 08, 2024)
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.
Attacker Value
Unknown

CVE-2023-1148

Disclosure Date: March 02, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1147

Disclosure Date: March 02, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1146

Disclosure Date: March 02, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1107

Disclosure Date: March 02, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1106

Disclosure Date: March 02, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1105

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1104

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.