PT-2025-21942 · Unknown · Flatpress Cms

Harish0X

·

Published

2025-05-19

·

Updated

2025-06-12

·

CVE-2025-44108

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Flatpress CMS versions prior to 1.4
Description: A stored Cross-Site Scripting (XSS) issue exists in the administration panel of Flatpress CMS via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Recommendations: For versions prior to 1.4, update to version 1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the administration panel and the gallery captions component to minimize the risk of exploitation. Avoid using the gallery captions component until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-44108

Affected Products

Flatpress Cms