📦 Funadmin

by Funadmin

🔍 What is Funadmin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36097

CRITICAL CVSS 9.8 Jun 22, 2023

Funadmin v3.3.2 and v3.3.3 contain an insecure file upload vulnerability in the plugins installation feature. Attackers can upload malicious files, potentially leading to remote code execution. Any sy...

CVE-2023-24774

CRITICAL CVSS 9.8 Mar 10, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at controller/auth/Auth.php. This allows attackers to execute arbitrary SQL commands, potentially compromising the ...

CVE-2023-24777

CRITICAL CVSS 9.8 Mar 8, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/table/list endpoint. This allows attackers to execute arbitrary SQL commands on the database. All systems runni...

CVE-2023-24782

CRITICAL CVSS 9.8 Mar 8, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/database/edit endpoint. This allows attackers to execute arbitrary SQL commands on the database. All systems ru...

CVE-2023-24780

CRITICAL CVSS 9.8 Mar 8, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the id parameter at /databases/table/columns endpoint. This allows attackers to execute arbitrary SQL commands on the database. Anyone running...

CVE-2023-24775

CRITICAL CVSS 9.8 Mar 7, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at /member/Member.php that allows attackers to execute arbitrary SQL commands. This affects all installations runni...

CVE-2023-24781

CRITICAL CVSS 9.8 Mar 7, 2023

Funadmin v3.2.0 contains a SQL injection vulnerability in the selectFields parameter at /member/MemberLevel.php. This allows attackers to execute arbitrary SQL commands on the database. Any organizati...

CVE-2023-24776

CRITICAL CVSS 9.8 Mar 6, 2023

Funadmin v3.2.0 contains a remote code execution vulnerability in the Addon.php controller component that allows attackers to execute arbitrary code on affected systems. This affects all installations...

CVE-2026-2896

HIGH CVSS 7.3 Feb 22, 2026

This vulnerability allows remote attackers to bypass authorization controls in funadmin's configuration handler, potentially enabling unauthorized configuration changes. It affects funadmin installati...

CVE-2024-48229

HIGH CVSS 7.2 Oct 25, 2024

CVE-2024-48229 is a SQL injection vulnerability in funadmin 5.0.2's Curd one-click command mode plugin. This allows attackers to execute arbitrary SQL commands on the database. All systems running the...

CVE-2024-48222

HIGH CVSS 7.2 Oct 25, 2024

Funadmin v5.0.2 contains a SQL injection vulnerability in the /curd/table/edit endpoint that allows attackers to execute arbitrary SQL commands. This affects all systems running the vulnerable version...

CVE-2024-48226

HIGH CVSS 7.2 Oct 25, 2024

Funadmin 5.0.2 contains a SQL injection vulnerability in the curd/table/savefield endpoint that allows attackers to execute arbitrary SQL commands. This affects all Funadmin 5.0.2 installations with t...

CVE-2026-2898

MEDIUM CVSS 5.5 Feb 22, 2026

This vulnerability allows remote attackers to execute arbitrary code through insecure deserialization in funadmin's AuthCloudService.php. Attackers can exploit the getMember function's cloud_account p...

CVE-2026-2894

MEDIUM CVSS 5.3 Feb 21, 2026

This vulnerability in funadmin allows remote attackers to exploit the getMember function in the forget.html login component to disclose sensitive information. It affects all funadmin installations up ...

CVE-2024-48224

MEDIUM CVSS 4.9 Oct 25, 2024

Funadmin v5.0.2 contains an arbitrary file read vulnerability in the /curd/index/editfile endpoint. This allows attackers to read sensitive files from the server filesystem. All systems running Funadm...

CVE-2026-2897

LOW CVSS 2.4 Feb 22, 2026

This is a cross-site scripting (XSS) vulnerability in funadmin's backend interface that allows attackers to inject malicious scripts into the application. The vulnerability affects funadmin versions u...