Vulnerabilities > Firefly III

DATE CVE VULNERABILITY TITLE RISK
2019-08-05 CVE-2019-14668 Cross-site Scripting vulnerability in Firefly-Iii Firefly III 4.7.17.3
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field.
network
low complexity
firefly-iii CWE-79
5.4
2019-08-05 CVE-2019-14667 Cross-site Scripting vulnerability in Firefly-Iii Firefly III 4.7.17.4
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name.
network
low complexity
firefly-iii CWE-79
6.1
2019-07-18 CVE-2019-13647 Cross-site Scripting vulnerability in Firefly-Iii Firefly III
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content.
network
low complexity
firefly-iii CWE-79
5.4
2019-07-18 CVE-2019-13646 Cross-site Scripting vulnerability in Firefly-Iii Firefly III
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query.
network
low complexity
firefly-iii CWE-79
5.4
2019-07-18 CVE-2019-13645 Cross-site Scripting vulnerability in Firefly-Iii Firefly III
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names.
network
low complexity
firefly-iii CWE-79
5.4
2019-07-18 CVE-2019-13644 Cross-site Scripting vulnerability in Firefly-Iii Firefly III
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name.
network
low complexity
firefly-iii CWE-79
5.4