Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

Flatsome Theme: Stored Cross-Site Scripting Can Steal User Data

CVE-2026-28083
Summary

The Flatsome theme has a security flaw that allows hackers to inject malicious code into websites built with this theme. This could lead to stolen user data and other sensitive information. Update to the latest version of Flatsome to fix this issue.

Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= ...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: from n/a through <= 3.20.1.
nvd CVSS3.1 6.5
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 26 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026