VYPR
Vendor

Admidio

Products
1
CVEs
61
Across products
61
Status
Private

Products

1

Recent CVEs

61
View all 61 CVEs →
  • CVE-2021-32630CriMay 20, 2021
    risk 0.63cvss 9.6epss 0.02

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload. A php web shell can be uploaded via the Documents & Files upload feature. Someone with upload…

  • CVE-2024-37906CriJul 29, 2024
    risk 0.57cvss 9.9epss 0.01

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The SQL Injection results in a…

  • CVE-2026-32817CriMar 20, 2026
    risk 0.52cvss 9.1epss 0.00

    Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delete folders or files. The folder_delete and file_delete action handlers in…

  • CVE-2024-38529CriJul 29, 2024
    risk 0.52cvss 9.0epss 0.01

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to upload a PHP file in the…

  • CVE-2026-32756HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.01

    Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within…

  • CVE-2017-6492HigMar 5, 2017
    risk 0.47cvss 7.2epss 0.01

    SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.

  • CVE-2026-47231HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` handler then operates on a *separate* URL…

  • CVE-2026-41670HigMay 7, 2026
    risk 0.46cvss 8.2epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML AuthnRequest messages as the destination for the SAML response, without…

  • CVE-2026-41669HigMay 7, 2026
    risk 0.46cvss 8.2epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call sites (handleSSORequest() line 418 and handleSLORequest() line 613). The method…

  • CVE-2026-32813HigMar 20, 2026
    risk 0.45cvss 8.0epss 0.00

    Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configuration feature lets authenticated users define custom list column layouts, storing user-supplied…

  • CVE-2023-3302HigJun 23, 2023
    risk 0.44cvss 7.8epss 0.00

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

  • CVE-2026-69091HigAug 3, 2026
    risk 0.42cvss 7.5epss 0.00

    Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum…

  • CVE-2026-34381HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.01

    Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded documents. The Docker image ships with AllowOverride None in the Apache configuration, which causes…

  • CVE-2025-62617HigOct 22, 2025
    risk 0.40cvss 7.2epss 0.00

    Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign members to a role (such as an…

  • CVE-2023-3692HigJul 16, 2023
    risk 0.40cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.

  • CVE-2026-41660HigMay 7, 2026
    risk 0.39cvss 7.1epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove their own TOTP configuration, but they can remove other users' TOTP, including…

  • CVE-2022-0991HigMar 19, 2022
    risk 0.39cvss 7.1epss 0.01

    Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

  • CVE-2026-42194MedMay 7, 2026
    risk 0.37cvss 6.8epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-based URL to curl_init(), leaving a DNS rebinding TOCTOU window that allows…

  • CVE-2026-41671MedMay 7, 2026
    risk 0.37cvss 6.8epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every request, regardless of whether a valid token is provided, whether the token is…

  • CVE-2026-32812MedMar 20, 2026
    risk 0.37cvss 6.8epss 0.00

    Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO Metadata API can result in SSRF and local file reads. The SSO Metadata fetch endpoint at modules/sso/fetch_metadata.php accepts an arbitrary URL via…