Cross-site scripting in Flarum - CVE-2021-32671
Published: June 6, 2021 / Updated: April 20, 2026
Flarum
Flarum
Description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the translation system when rendering user-supplied input as HTML DOM nodes. A remote attacker can submit malicious HTML markup to execute arbitrary script code in a victim's browser.
The issue can be triggered through certain user input fields, including the forum search box, and may allow actions to be performed on behalf of the victim.