Lucene search

K

FriendsOfFlarum Security Vulnerabilities

cve
cve

CVE-2022-35921

fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discussion disablement by users. Users of Byobu should update the extension to version 1.1.7, where this has been patched. Users of Byobu with Flarum 1.0 or 1.1 should upgrade to...

4.3CVSS

4.6AI Score

0.001EPSS

2022-08-01 10:15 PM
50
4
cve
cve

CVE-2022-30999

FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by...

8.7CVSS

5.9AI Score

0.001EPSS

2022-06-02 02:15 PM
71
5