CVE-2025-15549

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:fluentcms:fluentcms:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:12

Type Values Removed Values Added
Summary
  • (es) FluentCMS 2026 contiene una vulnerabilidad de cross-site scripting almacenado que permite a los administradores autenticados subir archivos SVG con JavaScript incrustado a través del módulo de Gestión de Archivos. Los atacantes pueden subir archivos SVG maliciosos que ejecutan JavaScript en el navegador de cualquier usuario que acceda a la URL del archivo subido.
First Time Fluentcms fluentcms
Fluentcms
CPE cpe:2.3:a:fluentcms:fluentcms:*:*:*:*:*:*:*:*
References () https://github.com/fluentcms/FluentCMS/issues/2404 - () https://github.com/fluentcms/FluentCMS/issues/2404 - Exploit, Vendor Advisory
References () https://www.vulncheck.com/advisories/fluentcms-stored-xss-via-svg-upload-in-file-management - () https://www.vulncheck.com/advisories/fluentcms-stored-xss-via-svg-upload-in-file-management - Third Party Advisory, VDB Entry

03 Mar 2026, 22:16

Type Values Removed Values Added
CWE CWE-79

23 Feb 2026, 17:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-79

30 Jan 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.8
v2 : unknown
v3 : unknown

29 Jan 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 20:16

Updated : 2026-03-10 18:12


NVD link : CVE-2025-15549

Mitre link : CVE-2025-15549

CVE.ORG link : CVE-2025-15549


JSON object : View

Products Affected

fluentcms

  • fluentcms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')