Flarum is a modestly represented but well-positioned forum software platform whose vulnerability profile centers on its core discussion application and related components. The exposure recurs through web-application weakness classes including cross-site scripting, missing authorization, cross-site request forgery, and improper access control—patterns typical of dynamic applications handling user input and session management at scale. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flarum over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32671CRITICAL Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be converted into HTML DOM nodes when rendered. This change was made a | Jun 7, 2021 | 10.0 | 51 | NO | NO |
CVE-2019-13183HIGH Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. | Jul 7, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-11514HIGH User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. | Apr 25, 2019 | 7.5 | 24 | NO | NO |
CVE-2024-21641MEDIUM Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users f | Jan 5, 2024 | 4.7 | 22 | NO | YES |
CVE-2023-40033HIGH Flarum is an open source forum software. Flarum is affected by a vulnerability that allows an attacker to conduct a Blind Server-Side Request Forgery (SSRF) attack or disclose any | Aug 16, 2023 | 7.1 | 21 | NO | NO |
CVE-2025-27794MEDIUM Flarum is open-source forum software. A session hijacking vulnerability exists in versions prior to 1.8.10 when an attacker-controlled authoritative subdomain under a parent domain | Mar 12, 2025 | 6.8 | 20 | NO | NO |
CVE-2023-22488MEDIUM Flarum is a forum software for building communities. Using the notifications feature, one can read restricted/private content and bypass access checks that would be in place for su | Jan 12, 2023 | 5.4 | 20 | NO | NO |
CVE-2018-19133MEDIUM In Flarum Core 0.1.0-beta.7.1, a serious leak can get everyone's email address. | Nov 9, 2018 | 5.3 | 20 | NO | NO |
CVE-2021-21283MEDIUM Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.0-beta.15 has a cross-site scripting vulnerability. A change | Jan 26, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-22487MEDIUM Flarum is a forum software for building communities. Using the mentions feature provided by the flarum/mentions extension, users can mention any post ID on the forum with the speci | Jan 11, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flarum.
Media articles that mention a CVE ID that affects a product developed by Flarum — matched by CVE ID, not by vendor name.