Friendica is a modestly scoped social-networking and federation platform whose vulnerability profile concentrates in its single core product and skews toward serious outcomes, with a meaningful share reaching critical severity. Its recurring weaknesses center on web-application input handling and authorization—including cross-site scripting, authorization bypass through user-controlled keys, information exposure, and memory-management issues—that reflect the complexity of user-generated content and access-control logic in federated social platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Friendica over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27730CRITICAL Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar | Aug 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2021-30141HIGH Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a | Apr 5, 2021 | 7.5 | 23 | NO | NO |
CVE-2024-27731MEDIUM Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parame | Aug 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-27729MEDIUM Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature. | Aug 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-27728MEDIUM Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature. | Aug 15, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-26495MEDIUM Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode t | Apr 3, 2024 | 6.1 | 17 | NO | NO |
CVE-2024-39094MEDIUM Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters. | Aug 20, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Friendica.
Media articles that mention a CVE ID that affects a product developed by Friendica — matched by CVE ID, not by vendor name.