CVE-2026-30913Disclosure

LOWCVSS 4.6 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpret as a hyperlink. The nickname is inserted verbatim into plain-text notification emails, and recipients may be misled into visiting attacker-controlled domains.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-10: 4Technical Details · 2026-03-10: 203-10
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-30913 Flarum Nickname Extension Email Injection Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30913

    Post summary

    The snippet references CVE‑2026‑30913, noting an Email Injection vulnerability in the Flarum Nickname Extension, but provides minimal detail and no evidence of exploitation, patches, or proof of concept.

    0001026
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30913 Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpre… https://www.cve.org/CVERecord?id=CVE-2026-30913

    Post summary

    This CVE concerns a flaw in Flarum’s nicknames extension that allows a registered user to set a nickname string interpreted by email clients, potentially leading to exploitation. No PoC, exploit, patch, or evidence of active exploitation is reported.

    00010264
    56.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30913 Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their nickname to a string that email clients interpre… https://www.cve.org/CVERecord?id=CVE-2026-30913 ----- Traducción: CVE-2026-30913 Fla… http://infoflow.cloud`

    Post summary

    The post cites CVE-2026-30913, noting that enabling the flarum/nicknames extension allows a registered user to set a nickname that can be interpreted by email clients, but it provides no PoC, exploitation details, patch, or technical specifics.

    0000037
    57 followersView on X
  • DailyCVE@dailycve
    General

    🟠 #Flarum, Input Validation Vulnerability, #CVE-2026-30913 (Medium) https://dailycve.com/flarum-input-validation-vulnerability-cve-2026-30913-medium/

    Post summary

    The post simply cites CVE-2026-30913 with a reference link, offering no additional evidence of PoC, exploit, active use, or mitigation.

    0000032
    167 followersView on X

Explore more