« Volver al listado

Firefly-iii

Firefly-iii Firefly III: vulnerabilidades y CVE

Firefly-iii Firefly III tiene 29 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE29
Últimos 12 meses2
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71250Media (4.3)0.28%—5 ago 2026
Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated…
CVE-2026-50886Crítica (9.1)0.44%—15 jun 2026
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
CVE-2024-37893Media (5.9)0.59%—17 jun 2024
Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow malicious users to bypass the MFA-check. This allows malicious users to use…
CVE-2024-22075Media (6.1)0.35%—5 ene 2024
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
CVE-2023-1788Crítica (9.8)0.44%—5 abr 2023
Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.
CVE-2023-1789Crítica (9.8)0.34%—1 abr 2023
Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0.
CVE-2023-0298Media (6.5)0.63%—14 ene 2023
Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0.
CVE-2021-4005Media (4.3)0.44%—4 dic 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4015Media (4.3)0.44%—1 dic 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3921Media (4.3)0.44%—13 nov 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3901Alta (8.8)0.55%—27 oct 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3900Media (6.5)0.55%—27 oct 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3851Media (5.4)0.57%—19 oct 2021
firefly-iii is vulnerable to URL Redirection to Untrusted Site
CVE-2021-3846Alta (8.8)0.78%—19 oct 2021
firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3819Alta (8.8)0.54%—27 sept 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3730Media (6.5)0.47%—23 ago 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3729Media (4.3)0.40%—23 ago 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3728Media (6.5)0.50%—23 ago 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3663Alta (7.5)0.71%—25 jul 2021
firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
CVE-2019-14672Media (5.4)0.74%—5 ago 2019
Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability name field. The JavaScript code is executed upon an error condition during a visit to the account…
CVE-2019-14671Baja (3.3)0.47%—5 ago 2019
Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to…
CVE-2019-14670Media (5.4)0.76%—5 ago 2019
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name field. The JavaScript code is executed during rule-from-bill creation.
CVE-2019-14669Media (5.4)0.76%—5 ago 2019
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset account name. The JavaScript code is executed during a visit to the audit account statistics page.
CVE-2019-14668Media (5.4)0.76%—5 ago 2019
Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction description field. The JavaScript code is executed during deletion of a transaction link.
CVE-2019-14667Media (6.1)1.3%—5 ago 2019
Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name. The JavaScript code is executed…
CVE-2019-13647Media (5.4)0.76%—18 jul 2019
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file content. The JavaScript code is executed during attachments/view/$file_id$ attachment viewing. NOTE:…
CVE-2019-13646Media (5.4)0.76%—18 jul 2019
Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search query. NOTE: It is asserted that an attacker must have the same access rights as the user in order…
CVE-2019-13645Media (5.4)0.76%—18 jul 2019
Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file names. The JavaScript code is executed during attachments/edit/$file_id$ attachment editing. NOTE: It…
CVE-2019-13644Media (5.4)0.76%—18 jul 2019
Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name. The JavaScript code is contained in a transaction, and is executed on the tags/show/$tag_number$…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application1
  2. T1526 Cloud Service Discovery1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.