CVE-2025-15549

MEDIUM

FluentCMS < 0.0.5 - Authenticated Stored Cross-Site Scripting via SVG File Upload

Title source: llm
STIX 2.1

Description

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

References (2)

Core 2

Scores

CVSS v3 4.8
EPSS 0.0023
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
fluentcms/fluentcms < 0.0.5
FluentCMS/FluentCMS < 0.0.5
Published Jan 29, 2026
Tracked Since Feb 18, 2026