CVE-2025-44108
MEDIUMFlatpress < 1.4 - Authenticated Stored Cross-Site Scripting via Gallery Captions
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-44108. PoCs published by harish0x.
AI-analyzed exploit summary This repository documents a stored XSS vulnerability (CVE-2025-44108) in FlatPress CMS 1.3.1, where an attacker with admin privileges can inject malicious JavaScript payloads into gallery captions, which execute when users visit the compromised page.
Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the administration panel of Flatpress CMS before 1.4 via the gallery captions component. An attacker with admin privileges can inject a malicious JavaScript payload into the system, which is then stored persistently.
Exploits (1)
This repository documents a stored XSS vulnerability (CVE-2025-44108) in FlatPress CMS 1.3.1, where an attacker with admin privileges can inject malicious JavaScript payloads into gallery captions, which execute when users visit the compromised page.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N