Vulnerabilities > Flatpress > Flatpress > 1.2.1

DATE CVE VULNERABILITY TITLE RISK
2023-03-02 CVE-2023-1146 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Generic in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-02 CVE-2023-1147 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-02 CVE-2023-1148 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
4.8
2023-03-02 CVE-2023-1106 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Reflected in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
6.1
2023-03-02 CVE-2023-1107 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-01 CVE-2023-1104 Cross-site Scripting vulnerability in Flatpress
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-79
5.4
2023-03-01 CVE-2023-1105 External Control of File Name or Path vulnerability in Flatpress
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-73
8.1
2023-02-22 CVE-2023-0947 Path Traversal vulnerability in Flatpress
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
network
low complexity
flatpress CWE-22
critical
9.8
2022-10-11 CVE-2022-40047 Cross-site Scripting vulnerability in Flatpress 1.2.1
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
network
low complexity
flatpress CWE-79
5.4
2022-09-29 CVE-2022-40048 Unrestricted Upload of File with Dangerous Type vulnerability in Flatpress 1.2.1
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
network
low complexity
flatpress CWE-434
7.2