CVE-2022-4822
- EPSS 0.31%
- Veröffentlicht 28.12.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:36:00
A vulnerability, which was classified as problematic, has been found in FlatPress. This issue affects some unknown processing of the file setup/lib/main.lib.php of the component Setup. The manipulation leads to cross site scripting. The attack may be...
CVE-2022-4821
- EPSS 0.31%
- Veröffentlicht 28.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:00
A vulnerability classified as problematic was found in FlatPress. This vulnerability affects the function onupload of the file admin/panels/uploader/admin.uploader.php of the component XML File Handler/MD File Handler. The manipulation leads to cross...
CVE-2022-4820
- EPSS 0.27%
- Veröffentlicht 28.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:36:00
A vulnerability classified as problematic has been found in FlatPress. This affects an unknown part of the file admin/panels/entry/admin.entry.list.php of the component Admin Area. The manipulation leads to cross site scripting. It is possible to ini...
CVE-2022-4755
- EPSS 0.27%
- Veröffentlicht 27.12.2022 10:15:11
- Zuletzt bearbeitet 21.11.2024 07:35:52
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument ...
CVE-2022-4748
- EPSS 0.65%
- Veröffentlicht 27.12.2022 09:15:09
- Zuletzt bearbeitet 21.11.2024 07:35:51
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the a...
CVE-2022-4605
- EPSS 0.34%
- Veröffentlicht 18.12.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 07:35:35
Cross-site Scripting (XSS) - Stored in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2022-4606
- EPSS 3.02%
- Veröffentlicht 18.12.2022 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:35:35
PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2022-40047
- EPSS 24.49%
- Veröffentlicht 11.10.2022 19:15:20
- Zuletzt bearbeitet 21.11.2024 07:20:46
Flatpress v1.2.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the page parameter at /flatpress/admin.php.
CVE-2022-40048
- EPSS 2.46%
- Veröffentlicht 29.09.2022 01:15:11
- Zuletzt bearbeitet 20.05.2025 20:15:24
Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
CVE-2021-41432
- EPSS 7.51%
- Veröffentlicht 23.06.2022 17:15:11
- Zuletzt bearbeitet 21.11.2024 06:26:14
A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaScript commands through blog content.