CVE-2026-56785 Details
Description
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers including administrators, or bypass URL scheme validation to inject javascript: or data: URIs.
A stored cross-site scripting vulnerability has been identified in FlatPress versions prior to commit 10be83c. This issue arises in the comment and contact forms, where the name, URL, and email fields are displayed without adequate output encoding in Smarty templates. As a result, attackers can inject arbitrary HTML and JavaScript into these fields, potentially executing malicious scripts in the browsers of viewers, including administrators. Additionally, the vulnerability allows for bypassing URL scheme validation to inject 'javascript:' or 'data:' URIs.
Users can update to the latest version of FlatPress, available on the official GitHub repository, to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FlatPress | <= 10be83c |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | [email protected] |
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion