CVE-2025-40722 Information

Description

Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro consisting of a stored XSS due to lack of proper validation of user input through the replace parameter in /config.php/tags.

Reference

https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-stored-cross-site-scripting-xss-vulnerabilities-flatboard-pro

CNNVD-202507-276 (Published: 2025-07-03)

Share on: