Flatcore is a small, focused content management system vendor whose product portfolio occupies a prominent niche among web publishing platforms. The vendor's vulnerability profile concentrates in its core CMS offering and recurs through application-layer input-handling and code-generation weaknesses: cross-site scripting, SQL injection, unrestricted file uploads, cross-site request forgery, and code injection flaws that are characteristic of web-facing administrative interfaces. These weakness classes align with the attack surface of a publicly accessible, user-configurable publishing system, where input validation boundaries and template rendering are critical control points. The vendor's disclosures have an elevated tendency to acquire public exploit code, reflecting the accessibility and appeal of CMS platforms to both security researchers and malicious actors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flatcore over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39608HIGH Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code. | Aug 23, 2021 | 7.2 | 60 | NO | YES |
CVE-2021-41403CRITICAL flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | Jun 15, 2022 | 9.8 | 38 | NO | NO |
CVE-2019-13961HIGH A CSRF vulnerability was found in flatCore before 1.5, leading to the upload of arbitrary .php files via acp/core/files.upload-script.php. | Jul 18, 2019 | 8.8 | 38 | NO | YES |
CVE-2019-10652HIGH An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .php files, related to the addons feature. | Mar 30, 2019 | 7.2 | 36 | NO | YES |
CVE-2017-7878CRITICAL SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database. | Apr 14, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-7877HIGH CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. | Apr 14, 2017 | 8.8 | 28 | NO | NO |
CVE-2021-41402HIGH flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code. | Jun 16, 2022 | 8.8 | 27 | NO | NO |
CVE-2017-8868HIGH acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted th | May 10, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-7879HIGH SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database. | Apr 14, 2017 | 7.5 | 24 | NO | NO |
CVE-2021-3745MEDIUM flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type | Oct 28, 2021 | 6.6 | 23 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flatcore.
Media articles that mention a CVE ID that affects a product developed by Flatcore — matched by CVE ID, not by vendor name.