Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Flarum

13 known vulnerabilities

2
CRITICAL
4
HIGH
6
MEDIUM
1
LOW

Top Products

flarum 12 sticky 1
13 CVEs
6.8
CVE-2025-27794

Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attac

6.5
CVE-2024-21641

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redire

7.1
CVE-2023-40033

Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blin

6.6
CVE-2023-27577

flarum is a forum software package for building communities. In versions prior to 1.7.0 an admin account which has alrea

3.5
CVE-2023-22489

Flarum is a discussion platform for websites. If the first post of a discussion is permanently deleted but the discussio

6.8
CVE-2023-22488

Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private co

7.7
CVE-2023-22487

Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extensio

9.0
CVE-2022-41938

Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HT

10.0
CVE-2021-32671

Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert

5.4
CVE-2021-21283

Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.

8.8
CVE-2019-13183

Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings.

7.5
CVE-2019-11514

User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.

5.3
CVE-2018-19133

In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address.

Frequently Asked Questions

How many CVEs affect Flarum?

Flarum has 13 CVE records in our database, including 2 critical and 4 high severity vulnerabilities.

What are the most severe Flarum vulnerabilities?

Flarum has 2 critical severity (CVSS 9.0+) and 4 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Flarum vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Flarum products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Flarum Vulnerabilities

CyberStrike scans your infrastructure for Flarum vulnerabilities and provides real-time remediation guidance.

Get Started