Логотип exploitDog
bind:CVE-2025-25460
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25460

Количество 3

Количество 3

nvd логотип

CVE-2025-25460

12 месяцев назад

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2025-25460

12 месяцев назад

A stored Cross-Site Scripting (XSS) vulnerability was identified in Fl ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-rfwv-x796-g3w9

12 месяцев назад

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-25460

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

CVSS3: 4.8
1%
Низкий
12 месяцев назад
debian логотип
CVE-2025-25460

A stored Cross-Site Scripting (XSS) vulnerability was identified in Fl ...

CVSS3: 4.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-rfwv-x796-g3w9

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.

CVSS3: 4.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу