CVE-2025-25460

A stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability allows authenticated attackers to inject malicious JavaScript payloads into blog posts, which are executed when other users view the posts. The issue arises due to improper input sanitization of the "TextArea" field in the blog entry submission form.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:flatpress:flatpress:1.3.1:*:*:*:*:*:*:*

History

12 Jun 2025, 20:14

Type Values Removed Values Added
CPE cpe:2.3:a:flatpress:flatpress:1.3.1:*:*:*:*:*:*:*
First Time Flatpress flatpress
Flatpress
References () https://github.com/flatpressblog/flatpress - () https://github.com/flatpressblog/flatpress - Product
References () https://github.com/RoNiXxCybSeC0101/CVE-2025-25460 - () https://github.com/RoNiXxCybSeC0101/CVE-2025-25460 - Exploit, Third Party Advisory

24 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-24 16:15

Updated : 2025-06-12 20:14


NVD link : CVE-2025-25460

Mitre link : CVE-2025-25460


JSON object : View

Products Affected

flatpress

  • flatpress
CWE

No CWE.