Known Vulnerabilities for products from Flatcore
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Flatcore".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-43118 json | A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML v... | 6.1 - MEDIUM | 2022-11-09 | 2022-11-09 |
| CVE-2021-42245 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.1 - MEDIUM | 2022-06-06 | 2022-06-14 |
| CVE-2021-41403 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2022-06-15 | 2022-06-24 |
| CVE-2021-41402 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-06-16 | 2022-06-28 |
| CVE-2021-40902 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2022-06-13 | 2022-06-17 |
| CVE-2021-40555 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2023-02-16 | 2023-02-24 |
| CVE-2021-39609 json | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. | 5.4 - MEDIUM | 2021-08-23 | 2022-07-28 |
| CVE-2021-39608 json | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote m... | 7.2 - HIGH | 2021-08-23 | 2021-09-14 |
| CVE-2021-23838 json | An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter ... | 4.8 - MEDIUM | 2021-01-15 | 2021-01-22 |
| CVE-2021-23837 json | An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selected_f... | 6.5 - MEDIUM | 2021-01-15 | 2021-01-22 |
| CVE-2021-23836 json | An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw H... | 4.8 - MEDIUM | 2021-01-15 | 2021-01-22 |
| CVE-2021-23835 json | An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the docs_... | 4.9 - MEDIUM | 2021-01-15 | 2021-01-22 |
| CVE-2021-3745 json | flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type | 6.6 - MEDIUM | 2021-10-28 | 2021-11-01 |
| CVE-2020-17452 json | flatCore before 1.5.7 allows upload and execution of a .php file by an admin. | 7.2 - HIGH | 2020-08-09 | 2020-08-10 |
| CVE-2020-17451 json | flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page... | 4.8 - MEDIUM | 2020-08-09 | 2020-08-10 |
| CVE-2019-13961 json | A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.uploa... | 8.8 - HIGH | 2019-07-18 | 2019-07-19 |
| CVE-2019-10652 json | An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php fi... | 7.2 - HIGH | 2019-03-30 | 2019-04-01 |
| CVE-2017-1000428 json | flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build link... | 6.1 - MEDIUM | 2018-01-10 | 2018-01-30 |
| CVE-2017-9451 json | Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary... | 6.1 - MEDIUM | 2017-06-06 | 2017-06-13 |
| CVE-2017-8868 json | acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.... | Not Provided | 2017-05-10 | 2025-04-20 |
Known software with vulnerabilities from Flatcore
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Flatcore | Flatcore | - |
| Application | Flatcore | Flatcore-cms | 1.0 |