CVE-2025-67349
Unknown
Unknown - Not Provided
Cross-Site Scripting in FluentCMS 1.2.3 Admin Add Page
Publication date: 2025-12-26
Last updated on: 2025-12-26
Assigner: MITRE
Description
Description
A cross-site scripting (XSS) vulnerability was identified in FluentCMS 1.2.3. After logging in as an admin and navigating to the "Add Page" function, the application fails to properly sanitize input in the <head> section, allowing remote attackers to inject arbitrary script tags.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| fluentcms | fluentcms | 1.2.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |