Логотип exploitDog
bind:CVE-2025-15549
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-15549

Количество 2

Количество 2

nvd логотип

CVE-2025-15549

10 дней назад

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

EPSS: Низкий
github логотип

GHSA-pvgm-mg5q-xc76

10 дней назад

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-15549

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

0%
Низкий
10 дней назад
github логотип
GHSA-pvgm-mg5q-xc76

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

CVSS3: 4.8
0%
Низкий
10 дней назад

Уязвимостей на страницу