flarum/core
[READ ONLY] Subtree split of Flarum framework core.
Activity
- Latest release
- Jul 08, 2026
- Total releases
- 74
- Cadence
- ~22 days
- Last 12 months
- 17
Reach
- Stars
- 21
Details
- License
- MIT
- First release
- Aug 27, 2015
| Version | Released | |
|---|---|---|
v2.0.0-rc.5
pre
|
v2.0.0-rc.5
pre
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
v2.0.0-rc.4
pre
| ||
v1.8.17
patch
|
v1.8.17
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v2.0.0-rc.3
pre
| ||
v2.0.0-rc.2
pre
|
v2.0.0-rc.2
pre
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
v1.8.16
patch
| ||
v2.0.0-rc.1
pre
|
v2.0.0-rc.1
pre
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
v1.8.15
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.8
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v1.8.14
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.7
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev |
v2.0.0-beta.7
pre
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
v1.8.13
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.6
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v1.8.12
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.5
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev |
v2.0.0-beta.5
pre
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
v2.0.0-beta.4
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v1.8.11
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.3
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v1.8.10
patch
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.2
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v2.0.0-beta.1
pre
1 CVE
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev | ||
v1.8.9
patch
2 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.8
patch
2 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev |
v1.8.8
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v1.8.7
patch
2 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.6
patch
2 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.5
patch
2 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.4
patch
3 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.8.3
patch
3 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev |
v1.8.3
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v1.8.2
patch
3 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.8.1
patch
3 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.8.0
minor
3 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.7.2
patch
4 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.7.2
patch
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
v1.7.1
patch
4 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.7.0
minor
4 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.6.3
patch
5 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.6.3
patch
Dependencies (48)
+ 40 more
Changelog
Compare changes
|
|
v1.6.2
patch
7 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.6.1
patch
8 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-41938
GHSA-7x4w-j98p-854x
Nov 21, 2022
Cross site scripting vulnerability with discussion titles
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. ImpactAll communities running Flarum from PatchesThe vulnerability has been fixed and published as flarum/core
You can then confirm you run the latest version using:
WorkaroundsNone For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/d/27558. For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.5.0
v1.6.0
v1.6.1
Fixed in
1.6.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.6.0
minor
8 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-41938
GHSA-7x4w-j98p-854x
Nov 21, 2022
Cross site scripting vulnerability with discussion titles
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. ImpactAll communities running Flarum from PatchesThe vulnerability has been fixed and published as flarum/core
You can then confirm you run the latest version using:
WorkaroundsNone For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/d/27558. For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.5.0
v1.6.0
v1.6.1
Fixed in
1.6.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.5.0
minor
8 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-41938
GHSA-7x4w-j98p-854x
Nov 21, 2022
Cross site scripting vulnerability with discussion titles
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. ImpactAll communities running Flarum from PatchesThe vulnerability has been fixed and published as flarum/core
You can then confirm you run the latest version using:
WorkaroundsNone For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/d/27558. For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.5.0
v1.6.0
v1.6.1
Fixed in
1.6.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.4.1
patch
7 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.1
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
v1.4.0
minor
7 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.3.1
patch
7 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.3.0
minor
7 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22489
GHSA-hph3-hv3c-7725
Jan 10, 2023
Any Flarum user including unactivated can reply in public discussions whose first post was permanently deleted
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
If the first post of a discussion is permanently deleted but the discussion stays visible, any actor who can view the discussion is able to create a new reply via the REST API, no matter the reply permission or lock status. This includes users that don't have a validated email. Guests cannot successfully create a reply because the API will fail with a 500 error when the user ID 0 is inserted into the database. This should also be fixed to return the expected 401/403 status. This happens because when the first post of a discussion is permanently deleted, the Flarum automatically makes discussions with zero comments invisible so an additional condition for this vulnerability is that the discussion must have at least one approved reply so that ImpactThis can open the discussion to uncontrolled spam or just unintentional replies if users still had their tab open before the vulnerable discussion was locked and then post a reply when they shouldn't be able to. In combination with the email notification settings, this could also be used as a way to send unsolicited emails. Versions between PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsIf you don't delete the first posts you are not affected. A workaround can be to delete the discussion itself, or amend the database to manually set a For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.2.1
patch
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.1
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
v1.2.0
minor
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.1.1
patch
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.1.0
minor
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.4
patch
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.4
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
v1.0.3
patch
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.2
patch
6 CVEs
CVE-2026-41887
GHSA-xjvc-pw2r-6878
Apr 22, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
SummaryFlarum's patch for CVE-2023-27577 restricted the Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary ImpactAn attacker who has compromised — or legitimately obtained — an administrator account can:
The contents of the attacker-controlled import are embedded into the compiled This is a privilege-escalation vulnerability: a forum administrator is not intended to have host-level file read or access to internal network resources. Example payloadSubmitted via
The setting is stored verbatim, interpolated into the LESS source on the next CSS compile, and the target file's contents appear in Patches
The fix extends the existing WorkaroundsIf upgrading is not immediately possible:
There is no configuration-level mitigation on affected versions — the fix requires the upgraded code. Resources
CreditReported to the Flarum Foundation by William (Liam) Snow IV (@LiamSnow), discovered during a graduate-level network security lab at Worcester Polytechnic Institute. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 55 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.10
v1.8.11
v1.8.12
v1.8.13
v1.8.14
v1.8.15
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
v2.0.0-beta.1
v2.0.0-beta.2
v2.0.0-beta.3
v2.0.0-beta.4
v2.0.0-beta.5
v2.0.0-beta.6
v2.0.0-beta.7
v2.0.0-beta.8
Fixed in
1.8.16
2.0.0-rc.1
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 41 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 36 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.4
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 31 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.7.2
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2023-27577
GHSA-vhm8-wwrf-3gcw
Mar 13, 2023
Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files
6.5
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
High
ImpactIf an admin account has already been compromised by an attacker, the An attacker can achieve this by providing an absolute path to a sensitive file in the custom
PatchesThe vulnerability has been addressed in version WorkaroundsUsers can mitigate the vulnerability by ensuring that their admin accounts are secured with strong passwords and other best practices for account security. Additionally, users can limit the exposure of sensitive files on the server by implementing appropriate file permissions and access controls. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 28 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
Fixed in
1.7.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2023-22488
GHSA-8gcg-vwmw-rxj4
Jan 10, 2023
Flarum notifications can leak restricted content
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for such content. The notification-sending component does not check that the subject of the notification can be seen by the receiver, and proceeds to send notifications through their different channels. The alerts do not leak data despite this as they are listed based on a visibility check, however, emails are still sent out. This means that, for extensions which restrict access to posts, any actor can bypass the restriction by subscribing to the discussion if the Subscriptions extension is enabled. ImpactThe attack allows the leaking of some posts in the forum database, including posts awaiting approval, posts in tags the user has no access to if they could subscribe to a discussion before it becomes private, and posts restricted by third-party extensions. Other leaks could also happen for different notification subjects if some features allowed to receive specific types of notifications for restricted content. All Flarum versions prior to v1.6.3 are affected. PatchesThe vulnerability has been fixed and published as flarum/core v1.6.3. All communities running Flarum should upgrade as soon as possible to v1.6.3 using:
You can then confirm you run the latest version using:
WorkaroundsDisable the Flarum Subscriptions extension or disable email notifications altogether. There is no other supported workaround for this issue for Flarum versions below 1.6.3. For more informationFor any questions or comments on this vulnerability please visit https://discuss.flarum.org/ For support questions create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 27 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.5.0
v1.6.0
v1.6.1
v1.6.2
Fixed in
1.6.3
References Updated Nov 08, 2023 · Source: OSV.dev |