CVE-2025-25460

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 79

Summary

CVE-2025-25460 is a stored Cross-Site Scripting (XSS) vulnerability affecting FlatPress 1.3.1. This issue lies in the "Add Entry" feature, where the "TextArea" field in the blog entry submission form fails to properly sanitize user input. Authenticated attackers can exploit this weakness by injecting malicious JavaScript payloads into blog posts. When other users view these compromised posts, the malicious scripts are executed, posing a significant security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share