Vulnerabilities > Firefly III > Firefly III > 3.1.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-19 | CVE-2021-3851 | Open Redirect vulnerability in Firefly-Iii Firefly III firefly-iii is vulnerable to URL Redirection to Untrusted Site | 5.4 |
2021-09-27 | CVE-2021-3819 | Cross-Site Request Forgery (CSRF) vulnerability in Firefly-Iii Firefly III firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | 8.8 |
2021-07-25 | CVE-2021-3663 | Improper Restriction of Excessive Authentication Attempts vulnerability in Firefly-Iii Firefly III firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts | 7.5 |
2019-07-18 | CVE-2019-13647 | Cross-site Scripting vulnerability in Firefly-Iii Firefly III Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. | 5.4 |
2019-07-18 | CVE-2019-13646 | Cross-site Scripting vulnerability in Firefly-Iii Firefly III Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. | 5.4 |
2019-07-18 | CVE-2019-13645 | Cross-site Scripting vulnerability in Firefly-Iii Firefly III Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. | 5.4 |
2019-07-18 | CVE-2019-13644 | Cross-site Scripting vulnerability in Firefly-Iii Firefly III Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. | 5.4 |