Funadmin
by Funadmin
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-2894 | Med | 0.34 | 5.3 | 0.00 | Feb 21, 2026 | A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly… | ||
| CVE-2024-48227 | Med | 0.32 | 4.9 | 0.01 | Oct 25, 2024 | Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). | ||
| CVE-2024-48224 | Med | 0.32 | 4.9 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. | ||
| CVE-2026-2895 | Low | 0.24 | 3.7 | 0.00 | Feb 21, 2026 | A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of… | ||
| CVE-2023-2477 | Low | 0.23 | 3.5 | 0.01 | May 2, 2023 | A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The… | ||
| CVE-2026-2897 | Low | 0.16 | 2.4 | 0.00 | Feb 22, 2026 | A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is… |
- risk 0.34cvss 5.3epss 0.00
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly…
- risk 0.32cvss 4.9epss 0.01
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
- risk 0.32cvss 4.9epss 0.01
Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.
- risk 0.24cvss 3.7epss 0.00
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of…
- risk 0.23cvss 3.5epss 0.01
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The…
- risk 0.16cvss 2.4epss 0.00
A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is…
Page 2 of 2