Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-2898 A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.p… Funadmin 7.1.0+ Fix from $1,6002026-02-22 MEDIUM 5.3 CVE-2026-2896 A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the co… Funadmin 7.1.0+ Fix from $1,6002026-02-22 CRITICAL 9.1 CVE-2026-2894 A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/lo… Funadmin 7.1.0+ Fix from $2,3002026-02-21 HIGH 8.1 CVE-2026-2895 A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Me… Funadmin 7.1.0+ Fix from $1,9502026-02-21 MEDIUM 6.1 CVE-2024-48228 An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values … Funadmin No fix yet Fix from $1,6002024-10-25 HIGH 7.2 CVE-2024-48229 funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. Funadmin Mitigation only Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48230 funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. Funadmin No fix yet Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48218 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. Funadmin No fix yet Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48222 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. Funadmin No fix yet Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48223 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. Funadmin No fix yet Fix from $1,9502024-10-25 HIGH 7.2 CVE-2024-48226 Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. Funadmin No fix yet Fix from $1,9502024-10-25 MEDIUM 6.5 CVE-2024-48225 Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. Funadmin No fix yet Fix from $1,6002024-10-25 HIGH 7.2 CVE-2024-48231 Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. Funadmin No fix yet Fix from $1,9502024-10-21 CRITICAL 9.8 CVE-2023-36097 funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. Funadmin No fix yet Fix from $2,3002023-06-22 MEDIUM 6.1 CVE-2023-2477 A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the… Funadmin after 3.2.3 Fix from $1,6002023-05-02 CRITICAL 9.8 CVE-2023-24774 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. Funadmin No fix yet Fix from $2,3002023-03-10 CRITICAL 9.8 CVE-2023-24777 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. Funadmin No fix yet Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-24782 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. Funadmin No fix yet Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-24773 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list. Funadmin No fix yet Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-24780 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. Funadmin No fix yet Fix from $2,3002023-03-08 CRITICAL 9.8 CVE-2023-24775EPSS 20% Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. Funadmin No fix yet Fix from $2,3002023-03-07 CRITICAL 9.8 CVE-2023-24781 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php. Funadmin No fix yet Fix from $2,3002023-03-07 CRITICAL 9.8 CVE-2023-24776 Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. Funadmin No fix yet Fix from $2,3002023-03-06