CVE-2026-56785Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers including administrators, or bypass URL scheme validation to inject javascript: or data: URIs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-23); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 106-2306-24
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-232
Disclosure2
2026-06-241
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-56785 (CVSS 8.2) - Stored XSS in FlatPress CMS affects comment/contact forms. Attackers can inject malicious scripts via name, URL, email fields. Update to commit 10be83c+ immediately. #CVE #PatchNow #ThreatIntel https://t.co/55UXiSa8aO

    Post summary

    A high‑severity stored XSS vulnerability (CVE‑2026‑56785) in FlatPress CMS is disclosed, with a specific patch commit recommended; no PoC or active exploitation is reported.

    0000047
    50 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56785 FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are re… https://www.cve.org/CVERecord?id=CVE-2026-56785 ----- Traducción: CVE-2026-56785 Fla… http://infoflow.cloud`

    Post summary

    The post announces a stored XSS vulnerability in FlatPress’s comment and contact forms, referencing the CVE record for further detail.

    0000030
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56785 FlatPress versions prior to commit 10be83c, contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are re… https://www.cve.org/CVERecord?id=CVE-2026-56785

    Post summary

    CVE‑2026‑56785 is a stored XSS issue in FlatPress comment/contact forms; the vulnerability is disclosed, with a patch commit (10be83c) referenced.

    00000699
    57.7K followersView on X

Explore more