Vulnerabilities
26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-2896 | A weakness has been identified in funadmin up to 7.1.0-rc4. A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 group max | <1% | PoC ×2 |
| — | |
| CVE-2026-2894 +1 in the same advisory: …2895 | A vulnerability was identified in funadmin up to 7.1.0-rc4. A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.5 group max | <1% | PoC ×2 |
| — | |
| CVE-2024-48222 | Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. NVD description · AI analysis pending | 7.2 group max | <1% | PoC |
| — | |
| CVE-2024-48231 | Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-36097 | funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-2477 | A vulnerability was found in Funadmin up to 3.2.3. A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-24774 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-24780 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-24775 +1 in the same advisory: …24781 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. NVD description · AI analysis pending | 9.8 | 20% | PoC |
| — | |
| CVE-2023-24776 | Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |