VYPR

Flaskbb

by Flaskbb

Source repositories

CVEs (3)

  • CVE-2026-46556MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Request Forgery (SSRF) vulnerability in get_image_info() allows any authenticated user to force the server to send HTTP requests to arbitrary internal endpoints,…

  • CVE-2026-22660HigJul 10, 2026
    risk 0.00cvss 7.2epss 0.00

    FlaskBB through 2.2.0, fixed in commit a5da9a5, contains a logic flaw vulnerability that allows authenticated administrators to delete all built-in authorization groups by exploiting a type mismatch in the bulk delete protection check. The bulk AJAX endpoint in the management…

  • CVE-2026-22659HigJul 10, 2026
    risk 0.00cvss 8.1epss 0.00

    FlaskBB through 2.2.0, fixed in commit acc88cf, contains an authorization bypass vulnerability that allows authenticated moderators to perform unauthorized actions on topics in forums they do not control by submitting crafted topic ID lists. Attackers can include a low-ID topic…