CVE-2025-67349: XSS
Published Dec 26, 2025
·Updated
A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.
Affected Software
2 affected components
FluentCMS FluentCMS
FluentCMS FluentCMS=1.2.3
Event History
Dec 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67349?
CVE-2025-67349 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-67349?
To fix CVE-2025-67349, update FluentCMS to the latest version that includes patches for this vulnerability.
3
Who is affected by CVE-2025-67349?
Administrators using FluentCMS version 1.2.3 are affected by CVE-2025-67349.
4
What type of vulnerability is CVE-2025-67349?
CVE-2025-67349 is a cross-site scripting (XSS) vulnerability that allows script injection.
5
Can CVE-2025-67349 be exploited remotely?
Yes, CVE-2025-67349 can be exploited remotely by attackers to inject arbitrary scripts.