grumpydictator/firefly-iii Security Advisories for v6.2.0 (2)
-
[CRITICAL] Project Firefly III has incorrect access control in the webhook management component
PKSA-1kzk-15h2-h7dj CVE-2026-50886 GHSA-9mmg-q95p-gp67
Affected version: <=6.5.9
Reported by:
GitHub -
[MEDIUM] Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)
PKSA-197r-m2ry-57db GHSA-6jq6-x4cx-qvcm
Affected version: <=6.6.2
Reported by:
GitHub