Technology · Packagist
flarum/core (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 8 vulnerabilities in flarum/core (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-27794, was published on 12 March 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About flarum/core (Packagist)
Flarum is an open-source forum software framework built with PHP and Mithril.js.
Latest flarum/core (Packagist) vulnerabilities
- CVE-2025-27794: Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie OverwritelowCVSS 3.1EPSS 0.5%
- CVE-2024-21641: Flarum's logout Route allows open redirectslowCVSS 3.1EPSS 1.1%
- CVE-2023-40033: Flarum vulnerable to LFI and Blind SSRF via Avatar uploadlowCVSS 3.1EPSS 0.5%
- CVE-2023-27577: Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server fileslowCVSS 3.1EPSS 0.9%
- CVE-2023-22489: Any Flarum user including unactivated can reply in public discussions whose first post was permanently deletedlowCVSS 3.1EPSS 0.6%
- CVE-2023-22488: Flarum notifications can leak restricted contentlowCVSS 3.1EPSS 0.4%
- CVE-2022-41938: Cross site scripting vulnerability with discussion titleslowCVSS 3.1EPSS 0.7%
- CVE-2021-32671: XSS vulnerability with translatorlowCVSS 3.1EPSS 39.7%
Most severe flarum/core (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-32671: XSS vulnerability with translatorlowCVSS 3.1EPSS 39.7%
- CVE-2024-21641: Flarum's logout Route allows open redirectslowCVSS 3.1EPSS 1.1%
- CVE-2023-27577: Path Traversal Vulnerability in `LESS` Parser allows reading of sensitive server fileslowCVSS 3.1EPSS 0.9%
- CVE-2022-41938: Cross site scripting vulnerability with discussion titleslowCVSS 3.1EPSS 0.7%
- CVE-2023-22489: Any Flarum user including unactivated can reply in public discussions whose first post was permanently deletedlowCVSS 3.1EPSS 0.6%
- CVE-2023-40033: Flarum vulnerable to LFI and Blind SSRF via Avatar uploadlowCVSS 3.1EPSS 0.5%
- CVE-2025-27794: Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie OverwritelowCVSS 3.1EPSS 0.5%
- CVE-2023-22488: Flarum notifications can leak restricted contentlowCVSS 3.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/flarum-core.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "flarum/core (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/flarum-core, 28 September 2026.