Product:

Firefly_iii

(Firefly\-Iii)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 26
Date Id Summary Products Score Patch Annotated
2019-07-18 CVE-2019-13644 Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability Firefly_iii 5.4
2019-07-18 CVE-2019-13645 Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability Firefly_iii 5.4
2019-07-18 CVE-2019-13646 Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability Firefly_iii 5.4
2019-07-18 CVE-2019-13647 Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability Firefly_iii 5.4
2024-01-05 CVE-2024-22075 Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection. Firefly_iii 6.1
2023-04-05 CVE-2023-1788 Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. Firefly_iii 9.8
2023-04-01 CVE-2023-1789 Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. Firefly_iii 9.8
2023-01-14 CVE-2023-0298 Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0. Firefly_iii 6.5
2021-12-04 CVE-2021-4005 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly_iii 4.3
2021-12-01 CVE-2021-4015 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly_iii 4.3