Bounties
Partners
Community
Info
flatpressblog / flatpress
Project repository
FlatPress is a lightweight, easy-to-set-up flat-file blogging engine.
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
147 DAYS
FIX
WITHIN
92 DAYS
Store Dom XSS in Widgets
Sep 2nd 2023
hainguyen0207
•
pending
Store XSS in International settings
Sep 2nd 2023
hainguyen0207
•
pending
Store XSS in Entries
Sep 2nd 2023
hainguyen0207
•
self closed
Store XSS at File Upload .html
Sep 2nd 2023
hainguyen0207
•
pending
Stored XSS via SVG File Upload
Apr 24th 2023
m0ck3d
•
self closed
Stored XSS
Apr 21st 2023
m0ck3d
•
pending
Reflected and Stored Cross-site Scripting (XSS) Vulnerabilities in Manage Static...
Mar 25th 2023
0xb4c
•
pending
XSS in Categories
Mar 23rd 2023
kkasdk
•
pending
Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Manage Entries and...
Mar 20th 2023
0xb4c
•
pending
Cross site scripting on Blog title
Mar 11th 2023
ghostbit11
•
pending
Cross site scripting on creating entries
Mar 11th 2023
ghostbit11
•
pending
Stored XSS on Editing page
Mar 2nd 2023
mike993
•
pending
stored xss in "Write Entry" module
Mar 1st 2023
christynorl
•
pending
File Upload Bypass Leads to Remote Code Execution (RCE)
Mar 1st 2023
choocs
•
pending
Unsanitized input that leads to XSS at Category Section
Mar 1st 2023
choocs
•
pending
FlatPress CMS Admin Panel File Upload Field Allows for JavaScript Payloads
Feb 27th 2023
paragbagul111
•
High
High
•
CVE-2024-9699
CVE-2024-9699
Directory Traversal Vulnerability in FlatPress CMS
Oct 2nd 2023
paragbagul111
•
informative
High
No Protection against Bruteforce attacks on Login page
Feb 27th 2023
choocs
•
pending
Cross-Site Request Forgery (CSRF) in FlatPress CMS Allows Enabling/Disabling of...
Feb 25th 2023
paragbagul111
•
High
High
•
CVE-2024-9847
CVE-2024-9847
Flatpress 1.2.1 Remote Command Execution via Arbitrary File upload
Jan 30th 2023
ameerassadi
•
pending
Reflected cross-site scripting in `page=` parameter
Jan 30th 2023
ameerassadi
•
pending
Cross-site Scripting (XSS) - Stored
Jan 26th 2023
d4rkp0w4r
•
pending
File upload to RCE by changing .htaccess
Apr 21st 2024
juylang
•
informative
Critical
Stored XSS via `.xsig` File in
Jan 8th 2023
juylang
•
High
High
•
CVE-2024-4023
CVE-2024-4023
Stored XSS via Character set parameter on admin.php?p=config
Jan 8th 2023
leorac
•
pending
Stored XSS via `.pages` File in
Mar 1st 2023
juylang
•
High
High
•
CVE-2023-1104
CVE-2023-1104
Send comment as admin through Improper Neutralization of Delimiters
Jan 2nd 2023
kos0ng
•
pending
Improper Input Validation lead to Arbitrary .txt File Deletion
Jan 2nd 2023
kos0ng
•
pending
Improper Filename Handling Mechanism lead to RCE
Jan 2nd 2023
kos0ng
•
pending
Stored XSS via blog author parameter on admin.php?p=config
Mar 1st 2023
leorac
•
Medium
Medium
•
CVE-2023-1146
CVE-2023-1146
Stored XSS through post comment body
Mar 1st 2023
leorac
•
Medium
Medium
•
CVE-2023-1147
CVE-2023-1147
Stored XSS on Option setting
Jan 8th 2023
baharuddinzulkifli
•
duplicate
Medium
Stored XSS via title, subtitle, footer and post title and content
Mar 1st 2023
leorac
•
Medium
Medium
•
CVE-2023-1148
CVE-2023-1148
The old session can be used after log out
Dec 26th 2022
uonghoangminhchau
•
pending
File Deletion Detected
Mar 1st 2023
juylang
•
High
High
•
CVE-2023-1105
CVE-2023-1105
Stored XSS via XML File
Mar 1st 2023
juylang
•
High
High
•
CVE-2023-1103
CVE-2023-1103
Stored XSS in multiple menus
Mar 1st 2023
uonghoangminhchau
•
Medium
Medium
•
CVE-2023-1107
CVE-2023-1107
Unsanitized input returned in response is conducive to XSS exploitation
Mar 1st 2023
und3sc0n0c1d0
•
Medium
Medium
•
CVE-2023-1106
CVE-2023-1106
Path traversal vulnerability found
Feb 22nd 2023
nilabhrajpoot
•
High
High
•
CVE-2023-0947
CVE-2023-0947
XSS STORED via SVG Upload
Jul 26th 2023
nilabhrajpoot
•
self closed
Php Remote file Inclusion and RCE
Dec 18th 2022
mike993
•
High
High
•
CVE-2022-4606
CVE-2022-4606
Stored XSS via SVG File
Dec 18th 2022
mike993
•
Medium
Medium
•
CVE-2022-4605
CVE-2022-4605
Cross Site Scripting with Write/Edit Entries.
Aug 19th 2022
lethanhtrung22
•
pending
Insufficient Session Expiration
Dec 3rd 2021
thelabda
•
pending
Cross-Site Request Forgery (CSRF)
Dec 3rd 2021
thelabda
•
pending
Cross-Site Request Forgery (CSRF)
Nov 26th 2021
khanhchauminh
•
pending
External Control of File Name or Path
Sep 2nd 2021
melbinkm
•
pending
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Oct 23rd 2021
melbinkm
•
Medium
•
$25
Medium
•
$25
Sensitive Cookie Without 'HttpOnly' Flag
Oct 1st 2022
melbinkm
•
Medium
Medium
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0