Unknown · Flatpress Cms · CVE-2025-44108
Name of the Vulnerable Software and Affected Versions:
Flatpress CMS versions prior to 1.4
Description:
A stored Cross-Site Scripting (XSS) issue exists in the administration panel of Flatpress CMS via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Recommendations:
For versions prior to 1.4, update to version 1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the administration panel and the gallery captions component to minimize the risk of exploitation. Avoid using the gallery captions component until the issue is resolved.