Flatnux is a content management system with a narrow product scope but elevated visibility in certain deployment contexts. The vendor's vulnerability profile is dominated by application-layer input-handling and code-generation weaknesses—cross-site scripting, cross-site request forgery, code injection, and path-traversal issues—that recur across the platform and reflect defenses typical of web-based content systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flatnux over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4878MEDIUM Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter | Sep 6, 2012 | 5.0 | 40 | NO | YES |
CVE-2012-4877MEDIUM Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators | Sep 6, 2012 | 6.8 | 30 | NO | YES |
CVE-2009-0572MEDIUM PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disab | Feb 13, 2009 | 5.1 | 25 | NO | YES |
CVE-2008-5761MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or HTML via (1) the mod paramete | Dec 30, 2008 | 4.3 | 21 | NO | YES |
CVE-2008-5759MEDIUM Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via the name parameter in an updat | Dec 30, 2008 | 4.3 | 21 | NO | YES |
CVE-2012-4892MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2012-03.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title_en, (2) su | Sep 10, 2012 | 4.3 | 17 | NO | NO |
CVE-2012-4890MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the n | Sep 10, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flatnux.
Media articles that mention a CVE ID that affects a product developed by Flatnux — matched by CVE ID, not by vendor name.