CVE-2019-13961: Flatcore

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.

Affected products

  • Flatcore Flatcore: before 1.5 (fixed in 1.5)

Published 2019-07-18. Last modified 2026-06-17.