Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
pkg:Packagist/
flarum/core
9 total CVEs
CRITICAL
2
HIGH
1
MEDIUM
5
LOW
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
10.0
CVE-2021-32671
XSS vulnerability with translator
>= 1.0.0, < 1.0.2
CRITICAL
9.0
CVE-2022-41938
Cross site scripting vulnerability with discussion titles
>= 1.5.0, < 1.6.2
HIGH
7.1
CVE-2023-40033
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
from 0, < 1.8.0
MEDIUM
6.8
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
from 0, < 1.8.10
MEDIUM
6.8
Flarum notifications can leak restricted content
from 0, < 1.6.3
MEDIUM
6.5
Flarum's logout Route allows open redirects
from 0, < 1.8.5
MEDIUM
6.5
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
from 0, < 1.7.0
MEDIUM
4.9
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
from 0, < 1.8.16
LOW
3.5
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
>= 1.3.0, < 1.6.3
CVE-2025-27794
CVE-2023-22488
CVE-2024-21641
CVE-2023-27577
CVE-2026-41887
CVE-2023-22489
Packagist/flarum/core — 9 CVEs · VulnScope