CVE-2026-32816
- EPSS 0.02%
- Veröffentlicht 19.03.2026 22:57:19
- Zuletzt bearbeitet 23.03.2026 19:10:21
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-roles/groups_roles.php perform destructive state changes on organizational roles but never validate an a...
CVE-2026-32755
- EPSS 0.02%
- Veröffentlicht 19.03.2026 22:53:09
- Zuletzt bearbeitet 23.03.2026 19:11:15
Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php saves changes to a member's role membership start and end dates but does not validate the CSRF token. ...
CVE-2026-30927
- EPSS 0.02%
- Veröffentlicht 09.03.2026 23:03:55
- Zuletzt bearbeitet 13.03.2026 14:45:47
Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event participation logic allows any user who can participate in an event to register OTHER users by manipulating the user_uuid GET paramet...
CVE-2025-62617
- EPSS 0.04%
- Veröffentlicht 22.10.2025 21:19:00
- Zuletzt bearbeitet 30.10.2025 17:15:48
Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionality of Admidio. Any authenticated user with permissions to assign membe...
CVE-2024-47836
- EPSS 1.62%
- Veröffentlicht 16.10.2024 20:15:06
- Zuletzt bearbeitet 05.03.2025 14:53:25
Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4.3.12 fixes this issue.
CVE-2024-38529
- EPSS 7.33%
- Veröffentlicht 29.07.2024 15:15:10
- Zuletzt bearbeitet 21.11.2024 09:26:12
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to...
CVE-2024-37906
- EPSS 0.92%
- Veröffentlicht 29.07.2024 15:15:10
- Zuletzt bearbeitet 21.11.2024 09:24:30
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The...
CVE-2023-47380
- EPSS 0.35%
- Veröffentlicht 22.11.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:13
Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-4190
- EPSS 0.56%
- Veröffentlicht 06.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:35
Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.
CVE-2023-3692
- EPSS 0.07%
- Veröffentlicht 16.07.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:17:51
Unrestricted Upload of File with Dangerous Type in GitHub repository admidio/admidio prior to 4.2.10.