Skip to main content

Vendor/product archive

firefly-iii / firefly_iii CVEs

Beta · best-effort

26 CVEs tagged to firefly-iii / firefly_iii2 Critical, 4 High, 19 Medium, 1 Low, 0 Unrated.

CVE-2019-14672

Published Aug 5, 2019

Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error con…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14671

Published Aug 5, 2019

Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. Thi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-14670

Published Aug 5, 2019

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14669

Published Aug 5, 2019

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14668

Published Aug 5, 2019

Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during d…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14667

Published Aug 5, 2019

Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account nam…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13647

Published Jul 18, 2019

Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13646

Published Jul 18, 2019

Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the s…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13645

Published Jul 18, 2019

Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2