Known Vulnerabilities for products from Flatpress

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Flatpress".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-1148 json Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. 4.8 - MEDIUM 2023-03-02 2023-03-03
CVE-2023-1147 json Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. 5.4 - MEDIUM 2023-03-02 2023-03-03
CVE-2023-1146 json Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3. 5.4 - MEDIUM 2023-03-02 2023-03-03
CVE-2023-1107 json Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. 5.4 - MEDIUM 2023-03-02 2023-03-03
CVE-2023-1106 json Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3. 6.1 - MEDIUM 2023-03-02 2023-03-03
CVE-2023-1105 json External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3. 8.1 - HIGH 2023-03-01 2023-03-09
CVE-2023-1104 json Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. 5.4 - MEDIUM 2023-03-01 2023-03-06
CVE-2023-1103 json ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further inv... Not Provided 2023-03-01 2023-11-07
CVE-2023-0947 json Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3. 9.8 - CRITICAL 2023-02-22 2023-03-02
CVE-2022-40048 json Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function. 7.2 - HIGH 2022-09-29 2022-09-29
CVE-2022-40047 json Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /fl... 5.4 - MEDIUM 2022-10-11 2022-10-13
CVE-2022-24588 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-02-15 2023-03-04
CVE-2022-4822 json A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing... 6.1 - MEDIUM 2022-12-28 2023-11-07
CVE-2022-4821 json A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the fil... 6.1 - MEDIUM 2022-12-28 2023-11-07
CVE-2022-4820 json A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/... 6.1 - MEDIUM 2022-12-28 2023-11-07
CVE-2022-4755 json A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plu... 6.1 - MEDIUM 2022-12-27 2023-11-07
CVE-2022-4748 json A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the fi... 9.8 - CRITICAL 2022-12-27 2023-11-07
CVE-2022-4606 json PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3. 9.8 - CRITICAL 2022-12-18 2022-12-22
CVE-2022-4605 json Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3. 5.4 - MEDIUM 2022-12-18 2022-12-22
CVE-2021-41432 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 5.4 - MEDIUM 2022-06-23 2022-06-29

Known software with vulnerabilities from Flatpress

Type Vendor Product Version
ApplicationFlatpressFlatpress0.804