Flatcore
23 known vulnerabilities
Top Products
Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via descripti
A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or H
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP co
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index p
FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sectio
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a rem
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_fi
An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selec
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_
An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title,
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .p
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbi
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
Frequently Asked Questions
How many CVEs affect Flatcore?
Flatcore has 23 CVE records in our database, including 2 critical and 8 high severity vulnerabilities.
What are the most severe Flatcore vulnerabilities?
Flatcore has 2 critical severity (CVSS 9.0+) and 8 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Flatcore vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Flatcore products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Flatcore Vulnerabilities
CyberStrike scans your infrastructure for Flatcore vulnerabilities and provides real-time remediation guidance.
Get Started