CVE-2025-44108

A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:*

History

12 Jun 2025, 16:26

Type Values Removed Values Added
First Time Flatpress flatpress
Flatpress
CPE cpe:2.3:a:flatpress:flatpress:*:*:*:*:*:*:*:*
References () https://github.com/flatpressblog/flatpress/commit/24a6feacf1747ec19725b52c097715c8ab9c4559 - () https://github.com/flatpressblog/flatpress/commit/24a6feacf1747ec19725b52c097715c8ab9c4559 - Patch
References () https://github.com/flatpressblog/flatpress/releases/tag/1.3.1 - () https://github.com/flatpressblog/flatpress/releases/tag/1.3.1 - Release Notes
References () https://github.com/flatpressblog/flatpress/releases/tag/1.4.rc2 - () https://github.com/flatpressblog/flatpress/releases/tag/1.4.rc2 - Release Notes
References () https://harish0x.github.io/blog/CVE-2025-44108 - () https://harish0x.github.io/blog/CVE-2025-44108 - Exploit, Third Party Advisory

21 May 2025, 20:25

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el panel de administración de Flatpress CMS (versión anterior a la 1.4) a través del componente de subtítulos de la galería. Un atacante con privilegios de administrador puede inyectar un payload de JavaScript maliciosa en el sistema, que posteriormente se almacena de forma persistente.

19 May 2025, 19:15

Type Values Removed Values Added
References () https://harish0x.github.io/blog/CVE-2025-44108 - () https://harish0x.github.io/blog/CVE-2025-44108 -
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

19 May 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 14:15

Updated : 2025-06-12 16:26


NVD link : CVE-2025-44108

Mitre link : CVE-2025-44108

CVE.ORG link : CVE-2025-44108


JSON object : View

Products Affected

flatpress

  • flatpress
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')