Known Vulnerabilities for products from Flarum

Listed below are 5 of the newest known vulnerabilities associated with the vendor "Flarum".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2023-40033 Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blind Ser... 7.1 - HIGH 2023-08-16 2023-08-16
CVE-2021-32671 Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted in... 10 - CRITICAL 2021-06-07 2021-06-17
CVE-2021-21283 Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-bet... 5.4 - MEDIUM 2021-01-26 2021-02-04
CVE-2019-13183 Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. 8.8 - HIGH 2019-07-07 2019-07-09
CVE-2019-11514 User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. 7.5 - HIGH 2019-04-25 2020-08-24
CVE-2018-19133 In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. 5.3 - MEDIUM 2018-11-09 2018-12-31

