Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2025-27794 Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attacker-controlled authoritative … Flarum 1.8.0+ Fix from $1,6002025-03-12 HIGH 7.1 CVE-2023-40033 Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blind Server-Side Request Forgery… Flarum 1.8.0+ Fix from $1,9502023-08-16 MEDIUM 5.4 CVE-2023-22488 Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access check… Flarum 1.6.3+ Fix from $1,6002023-01-12 MEDIUM 5.4 CVE-2022-41938 Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were … Flarum 1.6.2+ Fix from $1,6002022-11-19 CRITICAL 10.0 CVE-2021-32671EPSS 40% Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when r… Flarum Patch available Fix from $2,3002021-06-07 MEDIUM 5.4 CVE-2021-21283 Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site sc… Sticky Patch available Fix from $1,6002021-01-26 HIGH 8.8 CVE-2019-13183 Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. Flarum Mitigation only Fix from $1,9502019-07-07 HIGH 7.5 CVE-2019-11514 User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. Flarum Patch available Fix from $1,9502019-04-25 MEDIUM 5.3 CVE-2018-19133 In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. Flarum Patch available Fix from $1,6002018-11-09