flarum/core Security Advisories for v1.0.1 (6)
- 
                        [MEDIUM] Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie OverwritePKSA-wm5r-h6h3-m2pf CVE-2025-27794 GHSA-hg9j-64wp-m9px Affected version: <1.8.10 Reported by: 
 GitHub
- 
                        [MEDIUM] Flarum's logout Route allows open redirectsPKSA-t2c9-4b54-wr9g CVE-2024-21641 GHSA-733r-8xcp-w9mr Affected version: <1.8.5 Reported by: 
 GitHub
- 
                        [HIGH] Flarum vulnerable to LFI and Blind SSRF via Avatar uploadPKSA-gy61-rznj-1v67 CVE-2023-40033 GHSA-67c6-q4j4-hccg Affected version: <1.8.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server filesPKSA-vdnx-r1qz-p9z5 CVE-2023-27577 GHSA-vhm8-wwrf-3gcw Affected version: <1.7.0 Reported by: 
 GitHub
- 
                        [MEDIUM] Flarum notifications can leak restricted contentPKSA-c9jx-2v6m-svqv CVE-2023-22488 GHSA-8gcg-vwmw-rxj4 Affected version: <1.6.3 Reported by: 
 GitHub
- 
                        [CRITICAL] XSS vulnerability with translatorPKSA-wmpn-1w2t-mfh4 CVE-2021-32671 GHSA-5qjq-69w6-fg57 Affected version: >=1.0.0,<=1.0.1 Reported by: 
 GitHub