Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24864 | flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the user that made the post. At time of publication, there are no public patches available. |
Thu, 21 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 15 Aug 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dogukanurker
Dogukanurker flaskblog |
|
| Vendors & Products |
Dogukanurker
Dogukanurker flaskblog |
Thu, 14 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 Aug 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the user that made the post. At time of publication, there are no public patches available. | |
| Title | flaskBlog XSS Vulnerability in postContent | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-14T15:43:29.962Z
Reserved: 2025-07-07T14:20:38.389Z
Link: CVE-2025-53631
Updated: 2025-08-14T15:43:22.364Z
Status : Analyzed
Published: 2025-08-14T16:15:36.840
Modified: 2025-08-21T21:29:29.807
Link: CVE-2025-53631
No data.
OpenCVE Enrichment
Updated: 2025-08-15T08:17:35Z
EUVD