Funadmin
Products
1- 26 CVEs
Recent CVEs
26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-24775 | Cri | 0.65 | 9.8 | 0.20 | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. | ||
| CVE-2023-36097 | Cri | 0.64 | 9.8 | 0.01 | Jun 22, 2023 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. | ||
| CVE-2023-24774 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. | ||
| CVE-2023-24777 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. | ||
| CVE-2023-24782 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. | ||
| CVE-2023-24773 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list. | ||
| CVE-2023-24780 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. | ||
| CVE-2023-24781 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php. | ||
| CVE-2023-24776 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. | ||
| CVE-2026-2896 | Hig | 0.47 | 7.3 | 0.00 | Feb 22, 2026 | A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.… | ||
| CVE-2024-48230 | Hig | 0.47 | 7.2 | 0.00 | Oct 25, 2024 | funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | ||
| CVE-2024-48229 | Hig | 0.47 | 7.2 | 0.00 | Oct 25, 2024 | funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | ||
| CVE-2024-48226 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | ||
| CVE-2024-48223 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | ||
| CVE-2024-48222 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | ||
| CVE-2024-48218 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | ||
| CVE-2024-48231 | Hig | 0.47 | 7.2 | 0.01 | Oct 21, 2024 | Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. | ||
| CVE-2024-48225 | Med | 0.42 | 6.5 | 0.01 | Oct 25, 2024 | Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. | ||
| CVE-2024-48228 | Med | 0.40 | 6.1 | 0.00 | Oct 25, 2024 | An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS). | ||
| CVE-2026-2898 | Med | 0.36 | 5.5 | 0.00 | Feb 22, 2026 | A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be… |
- risk 0.65cvss 9.8epss 0.20
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
- risk 0.64cvss 9.8epss 0.01
funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
- risk 0.47cvss 7.3epss 0.00
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.…
- risk 0.47cvss 7.2epss 0.00
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
- risk 0.47cvss 7.2epss 0.00
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
- risk 0.47cvss 7.2epss 0.01
Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.
- risk 0.47cvss 7.2epss 0.01
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.
- risk 0.47cvss 7.2epss 0.01
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
- risk 0.42cvss 6.5epss 0.01
Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.
- risk 0.40cvss 6.1epss 0.00
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
- risk 0.36cvss 5.5epss 0.00
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be…