CVE-2025-44108: XSS
A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44108?
CVE-2025-44108 is classified as a stored Cross-Site Scripting (XSS) vulnerability, which can lead to serious security risks if exploited.
How do I fix CVE-2025-44108?
To fix CVE-2025-44108, upgrade to Flatpress CMS version 1.4 or later, which addresses this vulnerability.
Who is affected by CVE-2025-44108?
CVE-2025-44108 affects users of Flatpress CMS versions earlier than 1.4 with admin privileges.
What are the potential impacts of CVE-2025-44108?
Exploitation of CVE-2025-44108 could allow attackers to execute malicious JavaScript code in the context of the admin panel.
How can I identify if my Flatpress CMS is vulnerable to CVE-2025-44108?
You can identify if your Flatpress CMS is vulnerable to CVE-2025-44108 by checking if your version is below 1.4.