Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Reflected XSS.This issue affects Flexmls® IDX: from n/a through <= 3.15.9.
We have discovered 528 live websites that are affected by CVE-2026-25369.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 528 live websites (75% of Flexmls Idx install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 37 versions ( 95% of all versions) |
| 495 websites | |
| 14 websites | |
| 7 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 501 websites |
| .net | 15 websites |
| .info | 2 websites |
| .org | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *,***,*** | ||
| *******************************.com | *,***,*** | ||
| *********************.com | *,***,*** | ||
| ****************.com | *,***,*** | ||
| ***************.com | *,***,*** | ||
| **************.com | *,***,*** | ||
| *****************.com | *,***,*** | ||
| ***********************.com | *,***,*** | ||
| **************.com | *,***,*** | ||
| *************************.com | *,***,*** |
FAQ