Cross-site scripting in Flarum - CVE-2022-41938
Published: November 18, 2022 / Updated: April 20, 2026
Flarum
Flarum
Description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the page title system when rendering discussion titles as HTML DOM nodes. A remote user can create or rename a discussion with malicious HTML markup to execute arbitrary script in a victim's browser.
User interaction is required to open the relevant discussion page.