Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Moderate

CVE-2021-39609

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
Attacker Value
Unknown

CVE-2021-40555

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via description field on the new page creation form.
Attacker Value
Unknown

CVE-2022-43118

Disclosure Date: November 09, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field.
Attacker Value
Unknown

CVE-2021-41402

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
Attacker Value
Unknown

CVE-2021-41403

Disclosure Date: June 15, 2022 (last updated February 23, 2025)
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
Attacker Value
Unknown

CVE-2021-40902

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page.
Attacker Value
Unknown

CVE-2021-42245

Disclosure Date: June 06, 2022 (last updated February 23, 2025)
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections.
Attacker Value
Unknown

CVE-2021-3745

Disclosure Date: October 28, 2021 (last updated February 23, 2025)
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
Attacker Value
Unknown

CVE-2021-39608

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
Attacker Value
Unknown

CVE-2021-23835

Disclosure Date: January 15, 2021 (last updated February 22, 2025)
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_file HTTP request body parameter for the acp interface. This can be exploited with admin access rights. The affected parameter (which retrieves the contents of the specified file) was found to be accepting malicious user input without proper sanitization, thus leading to retrieval of backend server sensitive files, e.g., /etc/passwd, SQLite database files, PHP source code, etc.