VYPR

Material Admin

by Drupal

CVEs (3)

  • CVE-2026-30761HigMay 28, 2026
    risk 0.40cvss 7.3epss 0.00

    An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

  • CVE-2026-30760HigMay 28, 2026
    risk 0.40cvss 7.3epss 0.00

    An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

  • CVE-2025-3061Mar 31, 2025
    risk 0.00cvss epss 0.00

    Vulnerability in Drupal Material Admin.This issue affects Material Admin: *.*.