Apache / Fineract
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-57821 | Apache Fineract: Office list: SQL Injection via Subquery in orderBy | HIGH | 8.1 | Jul 15, 2026 |
| CVE-2026-35152 | Apache Fineract: SQL injection in runreports endpoint | HIGH | 8.8 | Jul 15, 2026 |
| CVE-2026-56287 | Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure | HIGH | 8.1 | Jul 15, 2026 |
| CVE-2025-58137 | Apache Fineract: IDOR via self-service API | HIGH | 8.1 | Dec 12, 2025 |
| CVE-2025-58130 | Apache Fineract: Server Key not masked | CRITICAL | 9.1 | Dec 12, 2025 |
| CVE-2025-23408 | Apache Fineract: weak password policy | HIGH | 8.5 | Dec 12, 2025 |
| CVE-2024-32838 | Apache Fineract: SQL injection vulnerabilities in offices API endpoint | CRITICAL | 9.4 | Feb 12, 2025 |
| CVE-2024-23537 | Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. | HIGH | 8.8 | Mar 29, 2024 |
| CVE-2024-23538 | Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipu… | CRITICAL | 9.9 | Mar 29, 2024 |
| CVE-2024-23539 | Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allow… | CRITICAL | 9.8 | Mar 29, 2024 |
| CVE-2023-25197 | apache fineract: SQL injection vulnerability in certain procedure calls | MEDIUM | 6.3 | Mar 28, 2023 |
| CVE-2023-25196 | Apache Fineract: SQL injection vulnerability | MEDIUM | 4.3 | Mar 28, 2023 |
| CVE-2023-25195 | Apache Fineract: SSRF template type vulnerability in certain authenticated users | HIGH | 8.1 | Mar 28, 2023 |
| CVE-2022-44635 | Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal | HIGH | 8.8 | Nov 29, 2022 |
| CVE-2020-17514 | disabled hostname verificiation | HIGH | 7.4 | May 27, 2021 |
| CVE-2018-20243 | The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues… | HIGH | 7.5 | Oct 13, 2020 |
| CVE-2018-11801 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table. | CRITICAL | 9.8 | Jun 11, 2019 |
| CVE-2018-11800 | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related ta… | CRITICAL | 9.8 | Jun 11, 2019 |
| CVE-2018-1292 | Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data… | HIGH | 8.1 | Apr 20, 2018 |
| CVE-2018-1291 | Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Pa… | HIGH | 8.1 | Apr 20, 2018 |
| CVE-2018-1290 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can… | CRITICAL | 9.8 | Apr 20, 2018 |
| CVE-2018-1289 | In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific… | HIGH | 8.8 | Apr 20, 2018 |
| CVE-2017-5663 | In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able… | HIGH | 8.8 | Dec 14, 2017 |
Showing 1 to 23 of 23 CVEs