Stored Cross-Site Scripting Vulnerability in FlatPress by FlatPress Team
CVE-2025-25460
What is CVE-2025-25460?
A stored Cross-Site Scripting (XSS) vulnerability has been detected in FlatPress version 1.3.1, specifically within the 'Add Entry' functionality. This vulnerability permits authenticated users to inject harmful JavaScript payloads into blog posts. The security risk stems from inadequate input sanitization of the 'TextArea' field when submitting blog entries, which allows the injected scripts to execute in the browsers of users who later view those posts. Ensuring robust input checks is crucial for maintaining the integrity and safety of user-generated content.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
