📦 Fineract

by Apache

🔍 What is Fineract?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-58130

CRITICAL CVSS 9.1 Dec 12, 2025

CVE-2025-58130 is an insufficiently protected credentials vulnerability in Apache Fineract that could allow attackers to access sensitive authentication data. This affects all Apache Fineract installa...

CVE-2025-58137

HIGH CVSS 8.1 Dec 12, 2025

This CVE describes an authorization bypass vulnerability in Apache Fineract where attackers can manipulate user-controlled keys to access unauthorized resources. It affects all Apache Fineract install...

CVE-2024-32838

HIGH CVSS 8.8 Feb 12, 2025

This SQL injection vulnerability in Apache Fineract allows authenticated attackers to inject malicious SQL queries through REST API endpoints like offices and dashboards. Attackers could potentially a...

CVE-2025-23408

MEDIUM CVSS 6.5 Dec 12, 2025

Apache Fineract versions through 1.10.1 have weak password requirements that allow attackers to set or maintain easily guessable passwords. This affects all organizations using vulnerable Fineract ins...

CVE-2023-25196

MEDIUM CVSS 4.3 Mar 28, 2023

This SQL injection vulnerability in Apache Fineract allows authorized users to manipulate SQL queries, potentially altering or adding data in certain components. It affects Apache Fineract versions 1....