CVE-2026-56785

Source
https://cve.org/CVERecord?id=CVE-2026-56785
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56785.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-56785
Published
2026-06-23T22:09:35.831Z
Modified
2026-07-15T01:48:56.185814223Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields
Details

FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers including administrators, or bypass URL scheme validation to inject javascript: or data: URIs.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56785.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "10be83c"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "*"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/flatpressblog/flatpress

Affected ranges

Type
GIT
Repo
https://github.com/flatpressblog/flatpress
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.1
1.2
1.2.1
1.2.beta1
1.2.beta2
1.3
1.3.beta1
1.3.rc1
1.4
1.4.1
1.4.rc1
1.4.rc2
1.5
1.5.1
1.5.rc1
1.5.rc2
v1.*
v1.0.2
v1.0.3
v1.0.3.php7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56785.json"