Vulnerabilities > Firefly III > Firefly III > 4.7.17.5

DATE CVE VULNERABILITY TITLE RISK
2021-07-25 CVE-2021-3663 Improper Restriction of Excessive Authentication Attempts vulnerability in Firefly-Iii Firefly III
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
network
low complexity
firefly-iii CWE-307
5.0
2019-08-05 CVE-2019-14672 Cross-site Scripting vulnerability in Firefly-Iii Firefly III 4.7.17.5
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field.
3.5