CVE-2026-2898
- EPSS 0.03%
- Veröffentlicht 22.02.2026 00:02:10
- Zuletzt bearbeitet 24.02.2026 16:27:39
A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deser...
CVE-2026-2897
- EPSS 0.02%
- Veröffentlicht 22.02.2026 00:02:08
- Zuletzt bearbeitet 24.02.2026 16:35:14
A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross si...
CVE-2026-2896
- EPSS 0.03%
- Veröffentlicht 21.02.2026 23:32:08
- Zuletzt bearbeitet 24.02.2026 16:38:14
A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attac...
CVE-2026-2895
- EPSS 0.08%
- Veröffentlicht 21.02.2026 23:15:59
- Zuletzt bearbeitet 24.02.2026 16:42:44
A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password reco...
CVE-2026-2894
- EPSS 0.03%
- Veröffentlicht 21.02.2026 23:15:59
- Zuletzt bearbeitet 24.02.2026 16:48:40
A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remote...
CVE-2024-48228
- EPSS 0.12%
- Veröffentlicht 25.10.2024 22:15:02
- Zuletzt bearbeitet 10.06.2025 18:46:12
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
CVE-2024-48230
- EPSS 0.13%
- Veröffentlicht 25.10.2024 21:15:04
- Zuletzt bearbeitet 31.10.2024 15:57:23
funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.
CVE-2024-48229
- EPSS 0.1%
- Veröffentlicht 25.10.2024 21:15:04
- Zuletzt bearbeitet 31.10.2024 15:49:11
funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.
CVE-2024-48227
- EPSS 0.09%
- Veröffentlicht 25.10.2024 21:15:04
- Zuletzt bearbeitet 31.10.2024 15:48:19
Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).
CVE-2024-48223
- EPSS 0.14%
- Veröffentlicht 25.10.2024 21:15:03
- Zuletzt bearbeitet 31.10.2024 15:44:25
Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.