VYPR

Fineract

by Apache

Source repositories

CVEs (23)

  • CVE-2026-57821HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.01

    A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission…

  • CVE-2026-56287HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.00

    A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an…

  • CVE-2026-35152HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.02

    A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporated into the generated SQL query without sufficient validation, allowing an authenticated user with…

Page 2 of 2