5.4 CVE-2025-55735

Exploit
 

flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe filter, that tells the engine to not escape the rendered content. This can lead to a stored XSS inside the content of the post. The code that causes the problem is in template/routes.html.
https://nvd.nist.gov/vuln/detail/CVE-2025-55735

Categories

CWE-79

References

security-advisories@github.com Exploit


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:dogukanurker:flaskblog:*:*:*:*:*:*:*:* <= 2.8.0


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
https://github.com/DogukanUrker/FlaskBlog/security/advisories/GHSA-gj9v-qhc3-...


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry