VYPR

Vendor CVEs

Admidio

All CVEs

65 total · sorted by risk
  • CVE-2026-47234MedAug 12, 2026
    risk 0.22cvss 4.4epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session…

  • CVE-2026-41656MedMay 7, 2026
    risk 0.22cvss 4.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php accepts a name parameter validated only as 'string' type (HTML encoding), allowing path traversal characters (../) to pass through unfiltered. Combined with…

  • CVE-2026-34384MedMar 31, 2026
    risk 0.22cvss 4.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in…

  • CVE-2026-82658MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.00

    Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the…

  • CVE-2026-47232MedAug 12, 2026
    risk 0.21cvss 4.3epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containing the configured private key and certificate, but the CSRF validation line is commented out. A forged…

  • CVE-2026-69094MedAug 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or…

  • CVE-2026-34383MedMar 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An…

  • CVE-2026-41663LowMay 7, 2026
    risk 0.16cvss 3.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire via GET requests with no CSRF token validation. Because SameSite=Lax cookies…

  • CVE-2024-47836LowOct 16, 2024
    risk 0.16cvss 3.5epss 0.00

    Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.

  • CVE-2023-3303LowJun 23, 2023
    risk 0.16cvss 3.5epss 0.00

    Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

  • CVE-2026-41659LowMay 7, 2026
    risk 0.11cvss 2.7epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, COUNTRY) in its SQL search condition regardless of field…

  • CVE-2026-82656LowAug 30, 2026
    risk 0.10cvss 2.6epss 0.00

    Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory…

  • CVE-2008-5209Nov 24, 2008
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

  • CVE-2021-43810HigDec 7, 2021
    risk 0.00cvss 8.8epss 0.05

    Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of…

  • CVE-2020-11004HigApr 24, 2020
    risk 0.00cvss 7.7epss 0.02

    SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie…

Page 2 of 2