Vulnerability Details CVE-2024-33209
FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them to execute arbitrary code in the context of a victim's web browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.047
EPSS Ranking 89.0%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-33209
-
cpe:2.3:a:flatpress:flatpress:1.3