← Back

Firefly Iii

firefly_iii

Vendor: Firefly Iii • 26 CVEs

CVEs (26)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Firefly Iii
1Firefly Iii
Jun 5, 2025
Jan 5, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Apr 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Apr 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Jan 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Dec 4, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Dec 1, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Nov 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Oct 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Oct 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Oct 19, 2021
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
firefly-iii is vulnerable to URL Redirection to Untrusted Site
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Oct 19, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Sep 27, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 23, 2021
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Jul 25, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show...Show more
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account show page.Show less
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 5, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/c...Show more
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.Show less
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
1Firefly Iii
1Firefly Iii
Nov 21, 2024
Aug 5, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.