Flintsh's vulnerability footprint concentrates in its Flare product, a narrowly scoped offering whose disclosures center on application-layer security issues including authorization bypass through user-controlled keys, path traversal, and cross-site scripting. These weaknesses are typical of web-facing applications and reflect input validation and access-control boundaries; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flintsh over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30230HIGH Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the thumbnail endpoint does not validate the password f | Mar 6, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-30942MEDIUM Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an authenticated path traversal vulnerability in /api/avatars/[ | Mar 10, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-30231MEDIUM Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.7.2, the raw and direct file routes only block unauthenticat | Mar 6, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-26993MEDIUM Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Versions 1.7.0 and below allow users to upload files without proper content val | Feb 20, 2026 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flintsh.
Media articles that mention a CVE ID that affects a product developed by Flintsh — matched by CVE ID, not by vendor name.