Impact
The vulnerability allows an attacker to inject arbitrary client‑side scripts through the TextHTML plugin in FluentCMS 1.2.3, potentially enabling session hijacking, data theft, defacement, or phishing attacks. The weakness is an uncontrolled script injection that can execute in the context of any user who views the affected content.
Affected Systems
FluentCMS 1.2.3, specifically the TextHTML plugin.
Risk and Exploitability
XSS vulnerabilities typically depend on the ability to submit user‑controlled input; in this case an attacker would need access to the content creation interface. While no current active exploit is listed in CISA KEV, the absence of rolling updates does not reduce the inherent risk. The exploitation probability is unknown but any vulnerability of this nature warrants immediate attention as it can be leveraged against authenticated or unauthenticated users depending on site configuration.
OpenCVE Enrichment