Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flatcore

First CVE: Apr 14, 2017Active for: 9 yearsTotal CVEs: 23
47.8
VTI Score
High

Flatcore is a small, focused content management system vendor whose product portfolio occupies a prominent niche among web publishing platforms. The vendor's vulnerability profile concentrates in its core CMS offering and recurs through application-layer input-handling and code-generation weaknesses: cross-site scripting, SQL injection, unrestricted file uploads, cross-site request forgery, and code injection flaws that are characteristic of web-facing administrative interfaces. These weakness classes align with the attack surface of a publicly accessible, user-configurable publishing system, where input validation boundaries and template rendering are critical control points. The vendor's disclosures have an elevated tendency to acquire public exploit code, reflecting the accessibility and appeal of CMS platforms to both security researchers and malicious actors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flatcore over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2017
9 years ago
Most Recent CVE
Feb 16, 2023
1,254 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-39608HIGH
Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.
Aug 23, 20217.260NOYES
CVE-2021-41403CRITICAL
flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.
Jun 15, 20229.838NONO
CVE-2019-13961HIGH
A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php.
Jul 18, 20198.838NOYES
CVE-2019-10652HIGH
An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature.
Mar 30, 20197.236NOYES
CVE-2017-7878CRITICAL
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
Apr 14, 20179.829NONO
CVE-2017-7877HIGH
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
Apr 14, 20178.828NONO
CVE-2021-41402HIGH
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.
Jun 16, 20228.827NONO
CVE-2017-8868HIGH
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted th
May 10, 20177.525NONO
CVE-2017-7879HIGH
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
Apr 14, 20177.524NONO
CVE-2021-3745MEDIUM
flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type
Oct 28, 20216.623NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
57%
35%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None11 (47.8%)
Unknown0 (0.0%)
Required12 (52.2%)
Privileges Required
Low5 (21.7%)
High8 (34.8%)
None10 (43.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flatcore.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flatcore — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flatcore's Products

View all 2 CNAs →

Top CWEs