VYPR
Vendor

Funadmin

Products
1
CVEs
26
Across products
26
Status
Private

Products

1

Recent CVEs

26
View all 26 CVEs →
  • CVE-2023-24775CriMar 7, 2023
    risk 0.65cvss 9.8epss 0.20

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.

  • CVE-2023-36097CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

  • CVE-2023-24774CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.

  • CVE-2023-24777CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.

  • CVE-2023-24782CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.

  • CVE-2023-24773CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.

  • CVE-2023-24780CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.

  • CVE-2023-24781CriMar 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.

  • CVE-2023-24776CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

  • CVE-2026-2896HigFeb 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely.…

  • CVE-2024-48230HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.00

    funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

  • CVE-2024-48229HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.00

    funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

  • CVE-2024-48226HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

  • CVE-2024-48223HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

  • CVE-2024-48222HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

  • CVE-2024-48218HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

  • CVE-2024-48231HigOct 21, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.

  • CVE-2024-48225MedOct 25, 2024
    risk 0.42cvss 6.5epss 0.01

    Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

  • CVE-2024-48228MedOct 25, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).

  • CVE-2026-2898MedFeb 22, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be…