Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flatpress MEDIUM 6.1
CVE-2025-29602

flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.

Fix: after 1.3.1
Fix from $1,600 2025-05-07
Flatpress HIGH 8.0
CVE-2024-9847

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf…

Fix: 1.4+
Fix from $1,950 2025-03-20
Flatpress MEDIUM 5.4
CVE-2024-9699

A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScr…

Fix: 1.4+
Fix from $1,600 2025-03-20
Flatpress HIGH 8.1
CVE-2024-4023

A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` extension …

Patch available
Fix from $1,950 2025-03-20
Flatpress HIGH 8.1
CVE-2024-41290

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

Mitigation only
Fix from $1,950 2024-10-02
Flatpress MEDIUM 5.4
CVE-2024-33209

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which …

No fix yet
Fix from $1,600 2024-10-02
Flatpress MEDIUM 5.4
CVE-2024-33210

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts in…

No fix yet
Fix from $1,600 2024-10-02
Flatpress MEDIUM 6.1
CVE-2024-25411

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

Fix: 1.3+
Fix from $1,600 2024-09-27
Flatpress MEDIUM 6.1
CVE-2024-25412

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

Fix: 1.3+
Fix from $1,600 2024-09-27
Flatpress MEDIUM 5.4
CVE-2023-1147

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 1.3+
Fix from $1,600 2023-03-02
Flatpress MEDIUM 5.4
CVE-2023-1146

Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 1.3+
Fix from $1,600 2023-03-02
Flatpress MEDIUM 5.4
CVE-2023-1107

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 1.3+
Fix from $1,600 2023-03-02
Flatpress MEDIUM 6.1
CVE-2023-1106

Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 1.3+
Fix from $1,600 2023-03-02
Flatpress HIGH 8.1
CVE-2023-1105

External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 2022-12-25+
Fix from $1,950 2023-03-01
Flatpress MEDIUM 5.4
CVE-2023-1104

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: 1.3+
Fix from $1,600 2023-03-01
Flatpress CRITICAL 9.8
CVE-2023-0947

Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: after 1.2.1
Fix from $2,300 2023-02-22
Flatpress MEDIUM 6.1
CVE-2022-4822

A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing of the file setup/lib/m…

Patch available
Fix from $1,600 2022-12-28
Flatpress MEDIUM 6.1
CVE-2022-4820

A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/entry/admin.entry.list.p…

Patch available
Fix from $1,600 2022-12-28
Flatpress MEDIUM 6.1
CVE-2022-4821

A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/…

Patch available
Fix from $1,600 2022-12-28
Flatpress MEDIUM 6.1
CVE-2022-4755

A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels…

Patch available
Fix from $1,600 2022-12-27
Flatpress CRITICAL 9.8
CVE-2022-4748

A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanag…

Patch available
Fix from $2,300 2022-12-27
Flatpress MEDIUM 5.4
CVE-2022-4605

Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: after 1.2.1
Fix from $1,600 2022-12-18
Flatpress CRITICAL 9.8
CVE-2022-4606EPSS 35%

PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.

Fix: after 1.2.1
Fix from $2,300 2022-12-18
Flatpress MEDIUM 5.4
CVE-2022-40047

Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.

No fix yet
Fix from $1,600 2022-10-11
Flatpress HIGH 7.2
CVE-2022-40048

Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.

No fix yet
Fix from $1,950 2022-09-29
Flatpress MEDIUM 5.4
CVE-2021-41432

A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog c…

No fix yet
Fix from $1,600 2022-06-23
Flatpress MEDIUM 5.4
CVE-2022-24588

Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.

No fix yet
Fix from $1,600 2022-02-15
Flatpress HIGH 8.8
CVE-2020-22761

Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.

Patch available
Fix from $1,950 2021-07-30