Apache Fineract
Apache · 21 CVEs
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Jul 15, 2026
Apache Fineract: SQL injection in runreports endpoint
Jul 15, 2026
Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Jul 15, 2026
Apache Fineract: IDOR via self-service API
Dec 12, 2025
Apache Fineract: Server Key not masked
Dec 12, 2025
Apache Fineract: weak password policy
Dec 12, 2025
Apache Fineract: SQL injection vulnerabilities in offices API endpoint
Feb 12, 2025
Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escala…
Mar 29, 2024
Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks,…
Mar 29, 2024
Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to…
Mar 29, 2024
apache fineract: SQL injection vulnerability in certain procedure calls
Mar 28, 2023
Apache Fineract: SQL injection vulnerability
Mar 28, 2023
Apache Fineract: SSRF template type vulnerability in certain authenticated users
Mar 28, 2023
Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal
Nov 29, 2022
disabled hostname verificiation
May 27, 2021
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a qu…
Jun 11, 2019
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a qu…
Jun 11, 2019
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hac…
Apr 20, 2018
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query…
Apr 20, 2018
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escap…
Apr 20, 2018
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different R…
Apr 20, 2018
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/cen…
Dec 14, 2017
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-57821 | Apache Fineract: Office list: SQL Injection via Subquery in orderBy | HIGH | 0.74% | Jul 15, 2026 |
| CVE-2026-35152 | Apache Fineract: SQL injection in runreports endpoint | HIGH | 3.28% | Jul 15, 2026 |
| CVE-2026-56287 | Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure | HIGH | 0.65% | Jul 15, 2026 |
| CVE-2025-58137 | Apache Fineract: IDOR via self-service API | HIGH | 0.39% | Dec 12, 2025 |
| CVE-2025-58130 | Apache Fineract: Server Key not masked | CRITICAL | 0.43% | Dec 12, 2025 |
| CVE-2025-23408 | Apache Fineract: weak password policy | HIGH | 0.52% | Dec 12, 2025 |
| CVE-2024-32838 | Apache Fineract: SQL injection vulnerabilities in offices API endpoint | CRITICAL | 1.54% | Feb 12, 2025 |
| CVE-2024-23537 | Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. | HIGH | 1.10% | Mar 29, 2024 |
| CVE-2024-23538 | Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipu… | CRITICAL | 1.29% | Mar 29, 2024 |
| CVE-2024-23539 | Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allow… | CRITICAL | 1.49% | Mar 29, 2024 |
| CVE-2023-25197 | apache fineract: SQL injection vulnerability in certain procedure calls | MEDIUM | 1.05% | Mar 28, 2023 |
| CVE-2023-25196 | Apache Fineract: SQL injection vulnerability | MEDIUM | 1.30% | Mar 28, 2023 |
| CVE-2023-25195 | Apache Fineract: SSRF template type vulnerability in certain authenticated users | HIGH | 0.98% | Mar 28, 2023 |
| CVE-2022-44635 | Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal | HIGH | 68.80% | Nov 29, 2022 |
| CVE-2020-17514 | disabled hostname verificiation | HIGH | 3.40% | May 27, 2021 |
| CVE-2018-11801 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table. | CRITICAL | 5.22% | Jun 11, 2019 |
| CVE-2018-11800 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related ta… | CRITICAL | 5.22% | Jun 11, 2019 |
| CVE-2018-1292 | Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data… | HIGH | 2.04% | Apr 20, 2018 |
| CVE-2018-1291 | Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Pa… | HIGH | 2.00% | Apr 20, 2018 |
| CVE-2018-1290 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can… | CRITICAL | 3.23% | Apr 20, 2018 |
| CVE-2018-1289 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific… | HIGH | 2.53% | Apr 20, 2018 |
| CVE-2017-5663 | In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able… | HIGH | 2.09% | Dec 14, 2017 |
Showing 1 to 21 of 21 CVEs