CVE-2024-39094
- EPSS 0.36%
- Veröffentlicht 20.08.2024 14:15:09
- Zuletzt bearbeitet 13.03.2025 16:15:20
Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix parameters.
CVE-2024-27728
- EPSS 0.23%
- Veröffentlicht 15.08.2024 19:15:18
- Zuletzt bearbeitet 04.06.2025 17:18:07
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the text parameter of the babel debug feature.
CVE-2024-27729
- EPSS 0.22%
- Veröffentlicht 15.08.2024 19:15:18
- Zuletzt bearbeitet 11.09.2024 20:29:52
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the location parameter of the calendar event feature.
CVE-2024-27730
- EPSS 5.59%
- Veröffentlicht 15.08.2024 19:15:18
- Zuletzt bearbeitet 04.06.2025 17:18:18
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.
CVE-2024-27731
- EPSS 0.23%
- Veröffentlicht 15.08.2024 19:15:18
- Zuletzt bearbeitet 04.06.2025 17:18:28
Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via the lack of file type filtering in the file attachment parameter.
CVE-2024-25864
- EPSS 0.86%
- Veröffentlicht 03.04.2024 03:15:09
- Zuletzt bearbeitet 13.03.2025 17:15:29
Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.
CVE-2024-26495
- EPSS 0.25%
- Veröffentlicht 03.04.2024 03:15:09
- Zuletzt bearbeitet 07.04.2025 14:25:49
Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.
CVE-2021-30141
- EPSS 0.47%
- Veröffentlicht 05.04.2021 23:15:12
- Zuletzt bearbeitet 21.11.2024 06:03:23
Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as demonstrated by an attempted access to an array offset on a value of type null, and excessive memory consumption. NOTE: the vendo...