Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefly Iii MEDIUM 6.1
CVE-2024-22075

Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.

Fix: 6.1.1+
Fix from $1,600 2024-01-05
Firefly Iii CRITICAL 9.8
CVE-2023-1788

Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

Fix: 6.0.0+
Fix from $2,300 2023-04-05
Firefly Iii CRITICAL 9.8
CVE-2023-1789

Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.

Fix: 5.7.18+
Fix from $2,300 2023-04-01
Firefly Iii MEDIUM 6.5
CVE-2023-0298

Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.

Fix: 5.8.0+
Fix from $1,600 2023-01-14
Firefly Iii HIGH 8.8
CVE-2021-3901

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 5.6.2
Fix from $1,950 2021-10-27
Firefly Iii MEDIUM 6.5
CVE-2021-3900

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: after 5.6.2
Fix from $1,600 2021-10-27
Firefly Iii HIGH 8.8
CVE-2021-3846

firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type

Fix: 5.6.2+
Fix from $1,950 2021-10-19
Firefly Iii MEDIUM 5.4
CVE-2021-3851

firefly-iii is vulnerable to URL Redirection to Untrusted Site

Fix: 5.6.2+
Fix from $1,600 2021-10-19
Firefly Iii HIGH 8.8
CVE-2021-3819

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Fix: 5.6.1+
Fix from $1,950 2021-09-27
Firefly Iii MEDIUM 6.5
CVE-2021-3728

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Patch available
Fix from $1,600 2021-08-23
Firefly Iii MEDIUM 6.5
CVE-2021-3730

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

Patch available
Fix from $1,600 2021-08-23
Firefly Iii HIGH 7.5
CVE-2021-3663

firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts

Fix: after 5.5.12
Fix from $1,950 2021-07-25
Firefly Iii MEDIUM 5.4
CVE-2019-14669

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code i…

Patch available
Fix from $1,600 2019-08-05
Firefly Iii MEDIUM 5.4
CVE-2019-14670

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is e…

Patch available
Fix from $1,600 2019-08-05
Firefly Iii MEDIUM 5.4
CVE-2019-14672

Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code…

Patch available
Fix from $1,600 2019-08-05
Firefly Iii MEDIUM 6.1
CVE-2019-14667

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description f…

Patch available
Fix from $1,600 2019-08-05
Firefly Iii MEDIUM 5.4
CVE-2019-14668

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaSc…

Patch available
Fix from $1,600 2019-08-05
Firefly Iii MEDIUM 5.4
CVE-2019-13644

Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is cont…

Fix: 4.7.17.1+
Fix from $1,600 2019-07-18
Firefly Iii MEDIUM 5.4
CVE-2019-13645

Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is e…

Fix: 4.7.17.3+
Fix from $1,600 2019-07-18
Firefly Iii MEDIUM 5.4
CVE-2019-13646

Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted th…

Fix: 4.7.17.3+
Fix from $1,600 2019-07-18
Firefly Iii MEDIUM 5.4
CVE-2019-13647

Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is…

Fix: 4.7.17.3+
Fix from $1,600 2019-07-18