CVE 4.8 MEDIUM

FluentCMS 2026 Stored XSS via SVG Upload in File Management_CVE-2025-15549

4.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Description

FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

Basic Information

ID CVE-2025-15549
Source VulnCheck
Published Jan 29, 2026 at 19:41
Modified Jan 29, 2026 at 20:20

Affected Product

Vendor FluentCMS
Product FluentCMS
Affected Versions FluentCMS FluentCMS 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.