Open-Source Forum Software Vulnerability in Flarum's Nickname Extension
CVE-2026-30913

4.6MEDIUM

Key Information:

Vendor

Flarum

Status
Vendor
CVE Published:
9 March 2026

What is CVE-2026-30913?

The Flarum open-source forum software contains a vulnerability in the flarum/nicknames extension. When this extension is active, registered users have the ability to set their nicknames to a format that email clients may treat as hyperlinks. This can mislead recipients of plain-text notification emails into clicking links that lead to attacker-controlled domains, exposing them to potential phishing attacks and security risks. It's essential for users and administrators to be aware of this issue and take necessary precautions to mitigate the risks.

Affected Version(s)

nicknames < 1.8.3

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.