VYPR

Poweradmin

by Poweradmin

Source repositories

CVEs (2)

  • CVE-2026-54588CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.01

    Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative source for building callback URLs in its OIDC, SAML, and logout authentication flows without any…

  • CVE-2026-47693MedJun 23, 2026
    risk 0.38cvss 6.9epss 0.00

    Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export functionality. User-controlled data — specifically the username field — is written to exported CSV…