CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Funadmin Remove filter Clear all
CVE-2026-7733 MEDIUM

funadmin Frontend Chunked Upload Endpoint UploadService.php chunkUpload unrestricted upload

CVSS 6.9 EPSS 0.50% May 4, 2026
CVE-2026-2898 MEDIUM

funadmin Backend Endpoint AuthCloudService.php getMember deserialization

CVSS 5.1 EPSS 0.45% Feb 22, 2026
CVE-2026-2897 MEDIUM

funadmin Backend index.html cross site scripting

CVSS 4.8 EPSS 0.37% Feb 22, 2026
CVE-2026-2896 MEDIUM

funadmin Configuration Ajax.php setConfig improper authorization

CVSS 6.9 EPSS 0.50% Feb 21, 2026
CVE-2026-2895 MEDIUM

funadmin Member.php repass password recovery

CVSS 6.3 EPSS 0.67% Feb 21, 2026
CVE-2026-2894 MEDIUM

funadmin forget.html getMember information disclosure

CVSS 6.9 EPSS 0.73% Feb 21, 2026
CVE-2024-48230 HIGH

funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

CVSS 8.9 EPSS 0.49% Oct 25, 2024
CVE-2024-48229 HIGH

funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

CVSS 8.9 EPSS 0.45% Oct 25, 2024
CVE-2024-48228 LOW

An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the p…

CVSS 2.1 EPSS 0.29% Oct 25, 2024
CVE-2024-48227 HIGH

Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).

CVSS 7.7 EPSS 0.55% Oct 25, 2024
CVE-2024-48226 HIGH

Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

CVSS 8.9 EPSS 0.56% Oct 25, 2024
CVE-2024-48225 HIGH

Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.

CVSS 7.8 EPSS 0.56% Oct 25, 2024
CVE-2024-48224 HIGH

Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.

CVSS 7.7 EPSS 0.65% Oct 25, 2024
CVE-2024-48223 HIGH

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

CVSS 8.9 EPSS 0.56% Oct 25, 2024
CVE-2024-48222 HIGH

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

CVSS 8.9 EPSS 0.58% Oct 25, 2024
CVE-2024-48218 HIGH

Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

CVSS 8.9 EPSS 0.56% Oct 25, 2024
CVE-2024-48231 HIGH

Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.

CVSS 8.6 EPSS 0.50% Oct 21, 2024
CVE-2023-36097 CRITICAL

funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

CVSS 9.8 EPSS 0.87% Jun 22, 2023
CVE-2023-2477 MEDIUM

Funadmin Cx.php tagLoad cross site scripting

CVSS 6.1 EPSS 0.55% May 2, 2023
CVE-2023-24774 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.

CVSS 9.8 EPSS 0.88% Mar 10, 2023
CVE-2023-24782 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.

CVSS 9.8 EPSS 0.74% Mar 8, 2023
CVE-2023-24777 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.

CVSS 9.8 EPSS 0.74% Mar 8, 2023
CVE-2023-24773 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.

CVSS 9.8 EPSS 0.74% Mar 8, 2023
CVE-2023-24781 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.

CVSS 9.8 EPSS 0.74% Mar 7, 2023
CVE-2023-24780 CRITICAL

Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.

CVSS 9.8 EPSS 0.81% Mar 7, 2023

Showing 1 to 25 CVEs · page 1 (more available)