Funadmin
by Funadmin
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-2896 | Hig | 0.47 | 7.3 | 0.00 | Feb 22, 2026 | A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.… | ||
| CVE-2026-2898 | Med | 0.36 | 5.5 | 0.00 | Feb 22, 2026 | A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be… | ||
| CVE-2026-2895 | Low | 0.24 | 3.7 | 0.00 | Feb 21, 2026 | A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of… | ||
| CVE-2026-2897 | Low | 0.16 | 2.4 | 0.00 | Feb 22, 2026 | A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is… | ||
| CVE-2023-24775 | 0.01 | — | 0.19 | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. | |||
| CVE-2026-2894 | 0.00 | — | 0.00 | Feb 21, 2026 | A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly… | |||
| CVE-2024-48224 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. | |||
| CVE-2024-48225 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. | |||
| CVE-2024-48226 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | |||
| CVE-2024-48222 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | |||
| CVE-2024-48223 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | |||
| CVE-2024-48230 | 0.00 | — | 0.00 | Oct 25, 2024 | funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | |||
| CVE-2024-48218 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | |||
| CVE-2024-48229 | 0.00 | — | 0.00 | Oct 25, 2024 | funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | |||
| CVE-2024-48227 | 0.00 | — | 0.01 | Oct 25, 2024 | Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). | |||
| CVE-2024-48228 | 0.00 | — | 0.00 | Oct 25, 2024 | An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS). | |||
| CVE-2024-48231 | 0.00 | — | 0.00 | Oct 21, 2024 | Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. | |||
| CVE-2023-36097 | 0.00 | — | 0.01 | Jun 22, 2023 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. | |||
| CVE-2023-2477 | 0.00 | — | 0.01 | May 2, 2023 | A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The… | |||
| CVE-2023-24774 | 0.00 | — | 0.01 | Mar 10, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. |
- risk 0.47cvss 7.3epss 0.00
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.…
- risk 0.36cvss 5.5epss 0.00
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be…
- risk 0.24cvss 3.7epss 0.00
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of…
- risk 0.16cvss 2.4epss 0.00
A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is…
- CVE-2023-24775Mar 7, 2023risk 0.01cvss —epss 0.19
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
- CVE-2026-2894Feb 21, 2026risk 0.00cvss —epss 0.00
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly…
- CVE-2024-48224Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
- CVE-2024-48225Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
- CVE-2024-48226Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
- CVE-2024-48222Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
- CVE-2024-48223Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
- CVE-2024-48230Oct 25, 2024risk 0.00cvss —epss 0.00
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
- CVE-2024-48218Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
- CVE-2024-48229Oct 25, 2024risk 0.00cvss —epss 0.00
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
- CVE-2024-48227Oct 25, 2024risk 0.00cvss —epss 0.01
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
- CVE-2024-48228Oct 25, 2024risk 0.00cvss —epss 0.00
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
- CVE-2024-48231Oct 21, 2024risk 0.00cvss —epss 0.00
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
- CVE-2023-36097Jun 22, 2023risk 0.00cvss —epss 0.01
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
- CVE-2023-2477May 2, 2023risk 0.00cvss —epss 0.01
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The…
- CVE-2023-24774Mar 10, 2023risk 0.00cvss —epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
Page 1 of 2