flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the user that made the post. At time of publication, there are no public patches available.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 21 Aug 2025 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Fri, 15 Aug 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Dogukanurker
Dogukanurker flaskblog
Vendors & Products Dogukanurker
Dogukanurker flaskblog

Thu, 14 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 15:30:00 +0000

Type Values Removed Values Added
Description flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the user that made the post. At time of publication, there are no public patches available.
Title flaskBlog XSS Vulnerability in postContent
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-08-14T15:43:29.962Z

Reserved: 2025-07-07T14:20:38.389Z

Link: CVE-2025-53631

cve-icon Vulnrichment

Updated: 2025-08-14T15:43:22.364Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-14T16:15:36.840

Modified: 2025-08-21T21:29:29.807

Link: CVE-2025-53631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-15T08:17:35Z