VYPR

ApiAdmin

by ApiAdmin

CVEs (2)

  • CVE-2026-88397Oct 5, 2026
    risk 0.00cvss —epss —

    ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.

  • CVE-2026-88396Oct 5, 2026
    risk 0.00cvss —epss —

    ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the…