Vulnerabilities > Firefly III > Firefly III > 5.6.4

DATE CVE VULNERABILITY TITLE RISK
2024-01-05 CVE-2024-22075 Cross-site Scripting vulnerability in Firefly-Iii Firefly III
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
network
low complexity
firefly-iii CWE-79
6.1
2023-01-14 CVE-2023-0298 Incorrect Authorization vulnerability in Firefly-Iii Firefly III
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
network
low complexity
firefly-iii CWE-863
6.5
2021-12-04 CVE-2021-4005 Cross-Site Request Forgery (CSRF) vulnerability in Firefly-Iii Firefly III
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
4.3