Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2025-29602
flatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.
Flatpress
after 1.3.1
HIGH 8.0
CVE-2024-9847
FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf…
Flatpress
1.4+
MEDIUM 5.4
CVE-2024-9699
A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScr…
Flatpress
1.4+
HIGH 8.1
CVE-2024-4023
A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` extension …
Flatpress
Patch available
HIGH 8.1
CVE-2024-41290
FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.
Flatpress
Mitigation only
MEDIUM 5.4
CVE-2024-33209
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which …
Flatpress
No fix yet
MEDIUM 5.4
CVE-2024-33210
A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts in…
Flatpress
No fix yet
MEDIUM 6.1
CVE-2024-25411
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…
Flatpress
1.3+
MEDIUM 6.1
CVE-2024-25412
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…
Flatpress
1.3+
MEDIUM 5.4
CVE-2023-1147
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
1.3+
MEDIUM 5.4
CVE-2023-1146
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
1.3+
MEDIUM 5.4
CVE-2023-1107
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
1.3+
MEDIUM 6.1
CVE-2023-1106
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
1.3+
HIGH 8.1
CVE-2023-1105
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
2022-12-25+
MEDIUM 5.4
CVE-2023-1104
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
1.3+
CRITICAL 9.8
CVE-2023-0947
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
after 1.2.1
MEDIUM 6.1
CVE-2022-4822
A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing of the file setup/lib/m…
Flatpress
Patch available
MEDIUM 6.1
CVE-2022-4820
A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/entry/admin.entry.list.p…
Flatpress
Patch available
MEDIUM 6.1
CVE-2022-4821
A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/…
Flatpress
Patch available
MEDIUM 6.1
CVE-2022-4755
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels…
Flatpress
Patch available
CRITICAL 9.8
CVE-2022-4748
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanag…
Flatpress
Patch available
MEDIUM 5.4
CVE-2022-4605
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
after 1.2.1
CRITICAL 9.8
CVE-2022-4606EPSS 35%
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
Flatpress
after 1.2.1
MEDIUM 5.4
CVE-2022-40047
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
Flatpress
No fix yet
HIGH 7.2
CVE-2022-40048
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
Flatpress
No fix yet
MEDIUM 5.4
CVE-2021-41432
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog c…
Flatpress
No fix yet
MEDIUM 5.4
CVE-2022-24588
Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
Flatpress
No fix yet
HIGH 8.8
CVE-2020-22761
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
Flatpress
Patch available