Arvid Zimmermann

1 exploit Active since May 2025
CVE-2025-44108 WRITEUP MEDIUM WRITEUP
Flatpress < 1.4 - Authenticated Stored Cross-Site Scripting via Gallery Captions
A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
CVSS 4.8