funadmin 漏洞与 CVE 列表(26)

产品(CPE): — CVE 数: 26

funadmin 漏洞概览

汇总 funadmin 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

历史漏洞主要涉及 SQL 注入与跨站脚本 等问题,部分漏洞可能导致 异常行为,并影响 生产负载与软件部署 相关场景。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 12026 CVE 数
«« 第一页 « 上一页 第 1 / 2 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-2898 A vulnerability was detected in funadmin up to 7.1.0-rc4. This issue affects the function getMember of the file app/common/service/AuthCloudService.php of the component Backend Endpoint. The manipulation of the argument cloud_account results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 2.0 0.04% 2026-02-22 2026-04-29
CVE-2026-2897 A security vulnerability has been detected in funadmin up to 7.1.0-rc4. This vulnerability affects unknown code of the file app/backend/view/index/index.html of the component Backend Interface. The manipulation of the argument Value leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 1.9 0.03% 2026-02-22 2026-04-29
CVE-2026-2896 A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 5.5 0.04% 2026-02-22 2026-04-29
CVE-2026-2895 A security flaw has been discovered in funadmin up to 7.1.0-rc4. Affected by this issue is the function repass of the file app/frontend/controller/Member.php. Performing a manipulation of the argument forget_code/vercode results in weak password recovery. Remote exploitation of the attack is possible. The attack's complexity is rated as high. The exploitation is known to be difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about th [email protected] 2.9 0.07% 2026-02-21 2026-04-29
CVE-2026-2894 A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulation leads to information disclosure. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. [email protected] 5.5 0.05% 2026-02-21 2026-02-24
CVE-2024-48228 An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS). [email protected] 6.1 0.17% 2024-10-25 2025-06-10
CVE-2024-48230 funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. [email protected] 7.2 0.18% 2024-10-25 2024-10-31
CVE-2024-48229 funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. [email protected] 7.2 0.12% 2024-10-25 2024-10-31
CVE-2024-48227 Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). [email protected] 4.9 0.06% 2024-10-25 2024-10-31
CVE-2024-48226 Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. [email protected] 7.2 0.12% 2024-10-25 2024-10-31
CVE-2024-48225 Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. [email protected] 6.5 0.10% 2024-10-25 2024-10-31
CVE-2024-48224 Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. [email protected] 4.9 0.18% 2024-10-25 2024-10-31
CVE-2024-48223 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. [email protected] 7.2 0.19% 2024-10-25 2024-10-31
CVE-2024-48222 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. [email protected] 7.2 0.19% 2024-10-25 2024-10-31
CVE-2024-48218 Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. [email protected] 7.2 0.19% 2024-10-25 2024-10-31
CVE-2024-48231 Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php. [email protected] 7.2 0.06% 2024-10-21 2025-06-10
CVE-2023-36097 funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install. [email protected] 9.8 0.40% 2023-06-22 2024-11-21
CVE-2023-2477 A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability. [email protected] 3.5 0.20% 2023-05-02 2024-11-21
CVE-2023-24774 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. [email protected] 9.8 1.27% 2023-03-10 2025-02-28
CVE-2023-24777 Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. [email protected] 9.8 0.25% 2023-03-08 2025-03-05
«« 第一页 « 上一页 第 1 / 2 页 下一页 »
cvelogic Threat Intelligence