VYPR

Admidio

by Admidio

Source repositories

CVEs (65)

  • CVE-2026-41659LowMay 7, 2026
    risk 0.11cvss 2.7epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, COUNTRY) in its SQL search condition regardless of field…

  • CVE-2026-82656LowAug 30, 2026
    risk 0.10cvss 2.6epss 0.00

    Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory…

  • CVE-2008-5209Nov 24, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2021-43810HigDec 7, 2021
    risk 0.00cvss 8.8epss 0.05

    Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of…

  • CVE-2020-11004HigApr 24, 2020
    risk 0.00cvss 7.7epss 0.02

    SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie…

Page 4 of 4