CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection. |
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. |
Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. |
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0. |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to URL Redirection to Untrusted Site |
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts |
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show...Show more |
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/c...Show more |
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation. |
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page. |