VYPR

Fineract

by Apache

Source repositories

CVEs (4)

  • CVE-2017-5663HigDec 14, 2017
    risk 0.57cvss 8.8epss 0.00

    In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.

  • CVE-2025-58137Dec 12, 2025
    risk 0.00cvss epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release.

  • CVE-2025-58130Dec 12, 2025
    risk 0.00cvss epss 0.00

    Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release.

  • CVE-2025-23408Dec 12, 2025
    risk 0.00cvss epss 0.00

    Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to upgrade to version 1.13.0, the latest release.