CVE security advisories and vulnerability history for firefly-iii by firefly-iii.
27
Total CVEs
Published
0
In CISA KEV
Exploited in the wild
4
Public exploits
With known exploit
5.3
Avg CVSS
2019–2024
Last updated
Overview
firefly-iii has 27 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 4 have a known public exploit. The average CVSS base score across scored CVEs is 5.3.
This page aggregates every publicly disclosed vulnerability (CVE) affecting firefly-iii, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of firefly-iii's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical0
High0
Medium17
Low1
9 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of firefly-iii's CVEs are currently listed in CISA's KEV catalog.
Public exploits
4
4 of firefly-iii's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every firefly-iii version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about firefly-iii vulnerabilities.
How many CVEs does firefly-iii firefly-iii have?
firefly-iii firefly-iii has 27 published CVE records since 2019.
How many firefly-iii firefly-iii CVEs are in CISA KEV?
None of firefly-iii firefly-iii's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Are there public exploits for firefly-iii firefly-iii vulnerabilities?
Yes — 4 of firefly-iii firefly-iii's CVEs have a known public exploit.
Which versions of firefly-iii firefly-iii are affected?
432 distinct firefly-iii firefly-iii versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in firefly-iii firefly-iii CVEs?
firefly-iii firefly-iii's CVEs most often map to these CWE weakness types: CWE-352 (Cross-Site Request Forgery (CSRF)), CWE-287 (Improper Authentication), CWE-307 (Improper Restriction of Excessive Authentication Attempts), CWE-434 (Unrestricted Upload of File with Dangerous Type).
What is the average severity of firefly-iii firefly-iii CVEs?
The average CVSS base score across firefly-iii firefly-iii's scored CVEs is 5.3.