CVE-2012-4890: Flatnux
Medium severity, CVSS 4.3. EPSS: 1.4% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.
Affected products
- Flatnux Flatnux: up to and including 2011-08-09-2; version 2008-12-11 only; version 2009-01-27 only; version 2009-02-04 only
Published 2012-09-10. Last modified 2026-06-16.