CVE Feed

    Dashboard / CVE / CVE-2025-15549

    CVE-2025-15549

    FluentCMS 2026 contains a stored cross-site scripting vulnerability that allows authenticated administrators to upload SVG files with embedded JavaScript via the File Management module. Attackers can upload malicious SVG files that execute JavaScript in the browser of any user accessing the uploaded file URL.

    Published:Jan 29, 2026
    Last Modified:Mar 10, 2026
    EPS:Jan 29, 2026
    EPSS Score:0.0001
    CVSS Score:4.8

    Affected Products

    Vendor
    Fluentcms
    Product
    Fluentcms

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High