Executive brief
FlatPress, a lightweight blogging engine, contains a security flaw in its comment and contact forms. Attackers can submit malicious code through the name, email, or website fields which then runs in the browser of anyone viewing the page, including site administrators. This could allow an attacker to hijack administrative sessions, steal sensitive information, or redirect visitors to malicious websites.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in FlatPress due to improper output encoding of user-supplied data in Smarty templates. Specifically, the 'name', 'URL', and 'email' fields in comment and contact forms are rendered without sufficient sanitization. An unauthenticated remote attacker can inject arbitrary HTML or JavaScript, or bypass URL scheme validation to inject 'javascript:' or 'data:' URIs. When a user or administrator views the affected content, the malicious script executes in their browser context. This can lead to session hijacking, unauthorized administrative actions, or data exfiltration. The issue was addressed in commit 10be83c.
Affected products
- FlatPress FlatPress Prior to commit 10be83c
Timeline
- 2026-04-15: patched: Fix committed to master branch
- 2026-06-23: disclosed: CVE published and advisory released