Vulnerabilities > Flatpress > Flatpress > 1.1

DATE CVE VULNERABILITY TITLE RISK
2023-03-02 CVE-2023-1146 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-02 CVE-2023-1147 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-02 CVE-2023-1148 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
4.8
2023-03-02 CVE-2023-1106 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
6.1
2023-03-02 CVE-2023-1107 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-01 CVE-2023-1104 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-01 CVE-2023-1105 External Control of File Name or Path vulnerability in Flatpress
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-73
8.1
2023-02-22 CVE-2023-0947 Path Traversal vulnerability in Flatpress
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-22
critical
9.8
2021-07-30 CVE-2020-22761 Cross-Site Request Forgery (CSRF) vulnerability in Flatpress 1.1
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
network
low complexity
flatpress CWE-352
8.8