FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.
References
| Link | Resource |
|---|---|
| https://github.com/fluentcms/FluentCMS/issues/2404 | Exploit Vendor Advisory |
| https://www.vulncheck.com/advisories/fluentcms-stored-xss-via-svg-upload-in-file-management | Third Party Advisory VDB Entry |
Configurations
History
10 Mar 2026, 18:12
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| First Time |
Fluentcms fluentcms
Fluentcms |
|
| CPE | cpe:2.3:a:fluentcms:fluentcms:*:*:*:*:*:*:*:* | |
| References | () https://github.com/fluentcms/FluentCMS/issues/2404 - Exploit, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/fluentcms-stored-xss-via-svg-upload-in-file-management - Third Party Advisory, VDB Entry |
03 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 |
23 Feb 2026, 17:23
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
| CWE |
30 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
29 Jan 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-29 20:16
Updated : 2026-03-10 18:12
NVD link : CVE-2025-15549
Mitre link : CVE-2025-15549
CVE.ORG link : CVE-2025-15549
JSON object : View
Products Affected
fluentcms
- fluentcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
