CVE-2026-47229
- EPSS 0.1%
- Veröffentlicht 12.08.2026 13:11:31
- Zuletzt bearbeitet 09.09.2026 20:55:04
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`. The `enable` case loads the SAML or OIDC client by UUID, calls `$clie...
CVE-2026-47228
- EPSS 0.11%
- Veröffentlicht 12.08.2026 13:09:18
- Zuletzt bearbeitet 09.09.2026 20:55:04
Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt hash in `adm_users.usr_password`, and emails the cleartext to that user. Every ...
CVE-2026-47227
- EPSS 0.24%
- Veröffentlicht 12.08.2026 12:58:29
- Zuletzt bearbeitet 09.09.2026 20:55:04
Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, …) corresponds to a module the actor administers. The follow-up "is this specific category editable by...
CVE-2026-47226
- EPSS 0.2%
- Veröffentlicht 12.08.2026 12:51:24
- Zuletzt bearbeitet 09.09.2026 20:55:04
Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can permanently delete files from folders where they have only view access. The authorization check at t...
CVE-2026-69094
- EPSS 0.16%
- Veröffentlicht 03.08.2026 13:20:47
- Zuletzt bearbeitet 09.09.2026 20:35:08
Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite ...
CVE-2026-69093
- EPSS 0.11%
- Veröffentlicht 03.08.2026 13:20:46
- Zuletzt bearbeitet 09.09.2026 20:35:08
Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated a...
CVE-2026-69092
- EPSS 0.23%
- Veröffentlicht 03.08.2026 13:20:45
- Zuletzt bearbeitet 09.09.2026 20:35:08
Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issue...
CVE-2026-69091
- EPSS 0.36%
- Veröffentlicht 03.08.2026 13:20:44
- Zuletzt bearbeitet 09.09.2026 20:35:08
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated...
CVE-2026-69090
- EPSS 0.2%
- Veröffentlicht 03.08.2026 13:20:44
- Zuletzt bearbeitet 09.09.2026 20:35:08
Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from...
CVE-2018-25370
- EPSS 0.19%
- Veröffentlicht 25.05.2026 14:15:15
- Zuletzt bearbeitet 23.07.2026 19:10:00
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious HTML forms targeting roles_function.php with paramet...