CVE-2022-41938

Cross site scripting vulnerability with discussion titles in flarum

Description

Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a discussion title input, either by creating a new discussion or renaming one. The XSS attack occurs after a visitor opens the relevant discussion page. All communities running Flarum from `v1.5.0` to `v1.6.1` are impacted. The vulnerability has been fixed and published as flarum/core `v1.6.2`. All communities running Flarum from `v1.5.0` to `v1.6.1` have to upgrade as soon as possible to v1.6.2. There are no known workarounds for this issue.

Category

9.0
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 0.56%
Vendor Advisory flarum.org
Affected: flarum framework
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2022-41938?
CVE-2022-41938 has been scored as a critical severity vulnerability.
How to fix CVE-2022-41938?
To fix CVE-2022-41938, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2022-41938 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2022-41938 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-41938?
CVE-2022-41938 affects flarum framework.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.