Vulnerabilities (CVE)

Filtered by vendor Flarum Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11514 1 Flarum 1 Flarum 2020-08-24 5.0 MEDIUM 7.5 HIGH
User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
CVE-2019-13183 1 Flarum 1 Flarum 2019-07-09 6.8 MEDIUM 8.8 HIGH
Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.