Apache Fineract

Apache · 21 CVEs

CVE-2026-57821
HIGH

Apache Fineract: Office list: SQL Injection via Subquery in orderBy

Jul 15, 2026

CVE-2026-35152
HIGH

Apache Fineract: SQL injection in runreports endpoint

Jul 15, 2026

CVE-2026-56287
HIGH

Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure

Jul 15, 2026

CVE-2025-58137
HIGH

Apache Fineract: IDOR via self-service API

Dec 12, 2025

CVE-2025-58130
CRITICAL

Apache Fineract: Server Key not masked

Dec 12, 2025

CVE-2025-23408
HIGH

Apache Fineract: weak password policy

Dec 12, 2025

CVE-2024-32838
CRITICAL

Apache Fineract: SQL injection vulnerabilities in offices API endpoint

Feb 12, 2025

CVE-2024-23537
HIGH

Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escala…

Mar 29, 2024

CVE-2024-23538
CRITICAL

Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks,…

Mar 29, 2024

CVE-2024-23539
CRITICAL

Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to…

Mar 29, 2024

CVE-2023-25197
MEDIUM

apache fineract: SQL injection vulnerability in certain procedure calls

Mar 28, 2023

CVE-2023-25196
MEDIUM

Apache Fineract: SQL injection vulnerability

Mar 28, 2023

CVE-2023-25195
HIGH

Apache Fineract: SSRF template type vulnerability in certain authenticated users

Mar 28, 2023

CVE-2022-44635
HIGH

Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal

Nov 29, 2022

CVE-2020-17514
HIGH

disabled hostname verificiation

May 27, 2021

CVE-2018-11801
CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a qu…

Jun 11, 2019

CVE-2018-11800
CRITICAL

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a qu…

Jun 11, 2019

CVE-2018-1292
HIGH

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hac…

Apr 20, 2018

CVE-2018-1291
HIGH

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query…

Apr 20, 2018

CVE-2018-1290
CRITICAL

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escap…

Apr 20, 2018

CVE-2018-1289
HIGH

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different R…

Apr 20, 2018

CVE-2017-5663
HIGH

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/cen…

Dec 14, 2017

Showing 1 to 21 of 21 CVEs