Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
flarum/nicknames extension has display name injection in notification emails (autolink & markdown) Moderate
CVE-2026-30913 was published for flarum/nicknames (Composer) Mar 10, 2026
imorland Credited to imorland and DavideIadeluca DavideIadeluca DavideIadeluca
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite Moderate
CVE-2025-27794 was published for flarum/core (Composer) Mar 12, 2025
novacuum Credited to novacuum, imorland, exside, and DavideIadeluca imorland imorland
exside exside DavideIadeluca DavideIadeluca
Flarum's logout Route allows open redirects Moderate
CVE-2024-21641 was published for flarum/core (Composer) Jan 5, 2024
imorland Credited to imorland, DavideIadeluca, and anonymous-nlp-student DavideIadeluca DavideIadeluca
anonymous-nlp-student anonymous-nlp-student
ProTip! Advisories are also available from the GraphQL API