VendorsFirefly IIIfirefly_iiiany version
Vulnerabilities

Firefly III Firefly Iii any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2023-1788
Insufficient Session Expiration in firefly-iii/firefly-iii
Published 2023-04-05 · Modified
9.8EPSS 0.004
CVE-2023-1789
Improper Input Validation in firefly-iii/firefly-iii
Published 2023-04-01 · Modified
9.8EPSS 0.003
CVE-2021-3846
Unrestricted Upload of File with Dangerous Type in firefly-iii/firefly-iii
Published 2021-10-19 · Modified
8.8EPSS 0.008
CVE-2021-3901
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-10-27 · Modified
8.8EPSS 0.006
CVE-2021-3819
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-09-27 · Modified
8.8EPSS 0.005
CVE-2021-3663
Improper Restriction of Excessive Authentication Attempts in firefly-iii/firefly-iii
Published 2021-07-25 · Modified
7.5EPSS 0.007
CVE-2023-0298
Incorrect Authorization in firefly-iii/firefly-iii
Published 2023-01-14 · Modified
6.5EPSS 0.006
CVE-2021-3900
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-10-27 · Modified
6.5EPSS 0.006
CVE-2021-3728
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-08-23 · Modified
6.5EPSS 0.005
CVE-2021-3730
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-08-23 · Modified
6.5EPSS 0.005
CVE-2024-22075
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
Published 2024-01-05 · Modified
6.1EPSS 0.003
CVE-2019-13645
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
Published 2019-07-18 · Modified
5.4EPSS 0.008
CVE-2019-13647
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
Published 2019-07-18 · Modified
5.4EPSS 0.008
CVE-2019-13646
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
Published 2019-07-18 · Modified
5.4EPSS 0.008
CVE-2019-13644
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$ tag summary page. NOTE: It is asserted that an attacker must have the same access rights as the user in order to be able to execute the vulnerability
Published 2019-07-18 · Modified
5.4EPSS 0.008
CVE-2021-3851
Open Redirect in firefly-iii/firefly-iii
Published 2021-10-19 · Modified
5.4EPSS 0.006
CVE-2021-3921
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-11-13 · Modified
5.4EPSS 0.004
CVE-2021-4015
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-12-01 · Modified
4.3EPSS 0.004
CVE-2021-4005
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-12-04 · Modified
4.3EPSS 0.004
CVE-2021-3729
Cross-Site Request Forgery (CSRF) in firefly-iii/firefly-iii
Published 2021-08-23 · Modified
4.3EPSS 0.004