Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Funadmin MEDIUM 6.5
CVE-2026-2898

A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p…

Fix: 7.1.0+
Fix from $1,600 2026-02-22
Funadmin MEDIUM 5.3
CVE-2026-2896

A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the co…

Fix: 7.1.0+
Fix from $1,600 2026-02-22
Funadmin CRITICAL 9.1
CVE-2026-2894

A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo…

Fix: 7.1.0+
Fix from $2,300 2026-02-21
Funadmin HIGH 8.1
CVE-2026-2895

A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Me…

Fix: 7.1.0+
Fix from $1,950 2026-02-21
Funadmin MEDIUM 6.1
CVE-2024-48228

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values …

No fix yet
Fix from $1,600 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48229

funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

Mitigation only
Fix from $1,950 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48230

funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

No fix yet
Fix from $1,950 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48218

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

No fix yet
Fix from $1,950 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48222

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

No fix yet
Fix from $1,950 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48223

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

No fix yet
Fix from $1,950 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48226

Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

No fix yet
Fix from $1,950 2024-10-25
Funadmin MEDIUM 6.5
CVE-2024-48225

Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

No fix yet
Fix from $1,600 2024-10-25
Funadmin HIGH 7.2
CVE-2024-48231

Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.

No fix yet
Fix from $1,950 2024-10-21
Funadmin CRITICAL 9.8
CVE-2023-36097

funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

No fix yet
Fix from $2,300 2023-06-22
Funadmin MEDIUM 6.1
CVE-2023-2477

A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the…

Fix: after 3.2.3
Fix from $1,600 2023-05-02
Funadmin CRITICAL 9.8
CVE-2023-24774

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.

No fix yet
Fix from $2,300 2023-03-10
Funadmin CRITICAL 9.8
CVE-2023-24777

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.

No fix yet
Fix from $2,300 2023-03-08
Funadmin CRITICAL 9.8
CVE-2023-24782

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.

No fix yet
Fix from $2,300 2023-03-08
Funadmin CRITICAL 9.8
CVE-2023-24773

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.

No fix yet
Fix from $2,300 2023-03-08
Funadmin CRITICAL 9.8
CVE-2023-24780

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.

No fix yet
Fix from $2,300 2023-03-08
Funadmin CRITICAL 9.8
CVE-2023-24775EPSS 20%

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.

No fix yet
Fix from $2,300 2023-03-07
Funadmin CRITICAL 9.8
CVE-2023-24781

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.

No fix yet
Fix from $2,300 2023-03-07
Funadmin CRITICAL 9.8
CVE-2023-24776

Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

No fix yet
Fix from $2,300 2023-03-06