Firefly III is a personal finance management application that serves as a self-hosted budgeting and accounting tool for individual users and small organizations. Despite a narrow product portfolio, the application occupies a more prominent position in vulnerability disclosures than its user base might suggest, reflecting the security scrutiny applied to open-source financial software. The vendor's vulnerability profile does not exhibit patterns of critical severity, widespread in-the-wild exploitation, or abundant public exploit availability, making it a lower-urgency tracking target compared to widely embedded or internet-facing software. Defenders deploying this application should treat updates as routine maintenance aligned with standard patch-management practices rather than as high-priority security incidents. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Firefly Iii over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1789CRITICAL Improper Input Validation in GitHub repository firefly-iii/firefly-iii prior to 6.0.0. | Apr 1, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-1788CRITICAL Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6. | Apr 5, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-3901HIGH firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | Oct 27, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-3846HIGH firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type | Oct 19, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-3663HIGH firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts | Jul 25, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-0298MEDIUM Incorrect Authorization in GitHub repository firefly-iii/firefly-iii prior to 5.8.0. | Jan 14, 2023 | 6.5 | 23 | NO | NO |
CVE-2021-3819HIGH firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | Sep 27, 2021 | 8.8 | 22 | NO | NO |
CVE-2021-3728MEDIUM firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | Aug 23, 2021 | 6.5 | 22 | NO | NO |
CVE-2019-14667MEDIUM Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in the transaction description field and the asset account name | Aug 5, 2019 | 6.1 | 21 | NO | NO |
CVE-2021-3851MEDIUM firefly-iii is vulnerable to URL Redirection to Untrusted Site | Oct 19, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Firefly Iii.
Media articles that mention a CVE ID that affects a product developed by Firefly Iii — matched by CVE ID, not by vendor name.