flarum/nicknames
[READ ONLY] Subtree split of Flarum nicknames extension.
Activity
- Latest release
- 2w ago
- Total releases
- 33
- Cadence
- ~39 days
- Last 12 months
- 14
Reach
- Stars
- 11
Details
- License
- MIT
- First release
- Dec 15, 2020
| Version | Released | |
|---|---|---|
v2.0.0-rc.8
pre
| ||
v2.0.0-rc.7
pre
| ||
v2.0.0-rc.6
pre
| ||
v2.0.0-rc.5
pre
| ||
v2.0.0-rc.4
pre
| ||
v2.0.0-rc.3
pre
| ||
v2.0.0-rc.2
pre
| ||
v2.0.0-rc.1
pre
| ||
v2.0.0-beta.8
pre
| ||
v1.8.3
patch
| ||
v2.0.0-beta.7
pre
| ||
v2.0.0-beta.6
pre
| ||
v2.0.0-beta.5
pre
| ||
v2.0.0-beta.4
pre
| ||
v2.0.0-beta.3
pre
| ||
v2.0.0-beta.2
pre
| ||
v2.0.0-beta.1
pre
| ||
v1.8.2
patch
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.8.1
patch
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.8.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.7.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.6.1
patch
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.6.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.5.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.4.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.3.1
patch
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.3.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.2.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.1.0
minor
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v1.0.0
initial
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
0.1.0-beta.16.1
pre
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v0.1.0-beta.16
pre
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev | ||
v0.1.0-beta.15
pre
1 CVE
CVE-2026-30913
GHSA-3c4m-j3g4-hh25
Mar 10, 2026
flarum/nicknames extension has display name injection in notification emails (autolink & markdown)
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryWhen the Affected package
Any third-party display name driver that permits special characters would be equally affected. Variants
Steps to reproduceVariant 1 (autolink — affects all email clients)
Variant 2 (markdown — affects markdown-rendering email clients)
ImpactPhishing / social engineering: victims may be misled into visiting attacker-controlled URLs via links appearing to originate from a trusted platform notification email. Variant 1 is exploitable against virtually all email clients without any special conditions.
Root causeThe default username-based display name driver constrains values to Proposed fix
References
Affected versions
0.1.0-beta.16.1
v0.1.0-beta.15
v0.1.0-beta.16
v1.0.0
v1.1.0
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.6.0
v1.6.1
+ 4 more Show less
v1.7.0
v1.8.0
v1.8.1
v1.8.2
Fixed in
1.8.3
References
Updated Mar 10, 2026 · Source: OSV.dev |