flarum/framework
Simple forum software for building great communities.
Activity
- Latest release
- Jul 08, 2026
- Total releases
- 70
- Cadence
- ~24 days
- Last 12 months
- 16
Reach
- Stars
- 6.7k
Details
- License
- MIT
- First release
- Aug 27, 2015
| Version | Released | |
|---|---|---|
v2.0.0-rc.5
pre
|
v2.0.0-rc.5
pre
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
v2.0.0-rc.4
pre
| ||
v1.8.17
patch
|
v1.8.17
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
v2.0.0-rc.3
pre
| ||
v2.0.0-rc.2
pre
|
v2.0.0-rc.2
pre
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
v1.8.16
patch
| ||
v2.0.0-rc.1
pre
|
v2.0.0-rc.1
pre
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
v1.8.15
patch
| ||
v2.0.0-beta.8
pre
| ||
v1.8.14
patch
| ||
v1.8.13
patch
| ||
v2.0.0-beta.6
pre
|
v2.0.0-beta.6
pre
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
v1.8.12
patch
| ||
v2.0.0-beta.5
pre
|
v2.0.0-beta.5
pre
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
v2.0.0-beta.4
pre
|
v2.0.0-beta.4
pre
Dependencies (56)
+ 48 more
Changelog
Compare changes
|
|
v1.8.11
patch
| ||
v2.0.0-beta.3
pre
| ||
v1.8.10
patch
| ||
v2.0.0-beta.2
pre
| ||
v2.0.0-beta.1
pre
| ||
v1.8.9
patch
1 CVE
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.8
patch
1 CVE
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev |
v1.8.8
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
v1.8.7
patch
1 CVE
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.6
patch
1 CVE
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.5
patch
1 CVE
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev | ||
v1.8.3
patch
2 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev |
v1.8.3
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
v1.8.2
patch
2 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.8.1
patch
2 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.8.0
minor
2 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev | ||
v1.7.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.7.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
v1.7.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.6.3
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.6.3
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v1.6.2
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.6.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.6.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.5.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.4.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.4.0
minor
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v1.3.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.3.1
patch
Dependencies (50)
+ 42 more
Changelog
Compare changes
|
|
v1.3.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.2.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.2.1
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
v1.2.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.1.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.1.0
minor
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.0.4
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev |
v1.0.4
patch
Dependencies (47)
+ 39 more
Changelog
Compare changes
|
|
v1.0.3
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.0.2
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.0.1
patch
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v1.0.0
initial
3 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev | ||
v0.1.0-beta.16
pre
4 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-19133
GHSA-p6m5-x83r-hqmr
May 14, 2022
Flarum Core Leaks PII
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. Affected versions
v0.1.0-beta
v0.1.0-beta.2
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
References Updated Feb 16, 2024 · Source: OSV.dev |
v0.1.0-beta.16
pre
Dependencies (44)
+ 36 more
Changelog
Compare changes
|
|
v0.1.0-beta.15
pre
4 CVEs
CVE-2025-27794
GHSA-hg9j-64wp-m9px
Mar 12, 2025
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
6.8
/ 10
Medium
Network
High
None
Required
Unchanged
High
High
None
SummaryA session hijacking vulnerability exists when an attacker-controlled authoritative subdomain under a parent domain (e.g., Key Constraints:
Due to non-existent session token rotation after authenticating we can theoretically reproduce the vulnerability by using browser dev tools, but due to the browser's security measures this does not seem to be exploitable as described. Proof of Concept (Deno)
Attack Flow
Why Reverse DNS Subdomains FailBrowsers block cookie setting for parent domains unless:
Example:
Browser Security Behavior1. Cookie Domain ValidationPer RFC 6265 §5.3:
2. Public Suffix List (PSL)Domains like
Verification:
Impact
Remediation
Revised Vulnerability CriteriaPrerequisites:
ReferencesAffected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 38 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.8.5
v1.8.6
v1.8.7
v1.8.8
v1.8.9
Fixed in
1.8.10
References
Updated Mar 12, 2025 · Source: OSV.dev
CVE-2024-21641
GHSA-733r-8xcp-w9mr
Jan 05, 2024
Flarum's logout Route allows open redirects
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
ImpactThe Flarum Some ecosystem extensions modifying the logout route have already been affected. Sample: https://discuss.flarum.org/d/22229-premium-wordpress-integration/526 PatchesThe vulnerability has been fixed and published as flarum/core v1.8.5. All communities running Flarum should upgrade as soon as possible to v1.8.5 using:
You can then confirm you run the latest version using:
WorkaroundsSome extensions modifying the logout route can remedy this issue if their implementation is safe. In any case we recommend updating to 1.8.5. ReferencesFor any questions or comments on this vulnerability, please visit https://discuss.flarum.org/ For support questions, create a discussion at https://discuss.flarum.org/t/support. A reminder that if you ever become aware of a security issue in Flarum, please report it to us privately by emailing security@flarum.org, and we will address it promptly. Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 33 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
v1.8.0
v1.8.1
v1.8.2
v1.8.3
Fixed in
1.8.5
References Updated Jan 17, 2025 · Source: OSV.dev
CVE-2023-40033
GHSA-67c6-q4j4-hccg
Aug 16, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
7.1
/ 10
High
Network
Low
Low
None
Unchanged
High
Low
None
ImpactThe Flarum forum software is affected by a vulnerability that allows an attacker to conduct a Blind SSRF attack or disclose any file on the server, even with a basic user account on any Flarum forum. By uploading a file containing a URL and spoofing the MIME type, an attacker can manipulate the application to execute unintended actions. The vulnerability is due to the behavior of the PatchesThis has been patched in Flarum v1.8. WorkaroundsAs a temporary workaround for the SSRF aspect of the vulnerability, one can disable PHP's CreditsAdam Kues - Assetnote Affected versions
v0.1.0-beta
v0.1.0-beta.10
v0.1.0-beta.11
v0.1.0-beta.11.1
v0.1.0-beta.12
v0.1.0-beta.13
v0.1.0-beta.14
v0.1.0-beta.14.1
v0.1.0-beta.15
v0.1.0-beta.16
v0.1.0-beta.2
v0.1.0-beta.3
+ 29 more Show less
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
v0.1.0-beta.7.2
v0.1.0-beta.8
v0.1.0-beta.8.1
v0.1.0-beta.8.2
v0.1.0-beta.9
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.7.0
v1.7.1
Fixed in
1.8.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-19133
GHSA-p6m5-x83r-hqmr
May 14, 2022
Flarum Core Leaks PII
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. Affected versions
v0.1.0-beta
v0.1.0-beta.2
v0.1.0-beta.3
v0.1.0-beta.4
v0.1.0-beta.5
v0.1.0-beta.6
v0.1.0-beta.7
v0.1.0-beta.7.1
References Updated Feb 16, 2024 · Source: OSV.dev |
v0.1.0-beta.15
pre
Dependencies (44)
+ 36 more
Changelog
Compare changes
|