CVE-2021-32671 is a critical cross-site scripting (XSS) vulnerability affecting Flarum forum software versions 1.0.0 and 1.0.1. The flaw allowed malicious HTML markup entered into user input fields, such as the search box, to be rendered as active DOM nodes, leading to client-side code execution. With a CVSS score of 10.0, this vulnerability poses a severe risk, enabling attackers to perform actions like deleting discussions, modifying user settings, or even compromising administrative panels if targeting privileged users. While no active exploitation or public exploit code has been identified, and community discussion is minimal, immediate patching to Flarum v1.0.2 is strongly recommended due to the high potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:flarum:flarum:1.0.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:flarum:flarum:1.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.