Admidio/admidio
This hub aggregates every CVE we track for Admidio/admidio, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
20
CVEs tracked
2
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM10HIGH6LOW2CRITICAL2
Monthly trend
2
0
0
1
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
6
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Admidio/admidio.
- CVE-2026-32813Admidio: Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)8.0
- CVE-2026-32812Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint6.8
- CVE-2026-32757Admidio: HTMLPurifier Bypass in eCard Message Allows HTML Email Injection5.4
- CVE-2026-32756Admidio: Unrestricted File Upload via CSRF Token Validation Bypass in Documents & Files Module8.8
- CVE-2026-32755Admidio is Missing CSRF Protection on Role Membership Date Changes5.7
- CVE-2026-30927Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid parameter5.4
- CVE-2025-62617Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality7.2
- CVE-2024-47836Admidio vulnerable to HTML Injection In The Messages Section3.5
- CVE-2024-38529Admidio Vulnerable to RCE via Arbitrary File Upload in Message Attachment9.0
- CVE-2024-37906Admidio has Blind SQL Injection in ecard_send.php9.9
- CVE-2023-47380Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).6.1
- CVE-2023-4190Insufficient Session Expiration in admidio/admidio6.5
- CVE-2023-3692Unrestricted Upload of File with Dangerous Type in admidio/admidio7.2
- CVE-2023-3304Improper Access Control in admidio/admidio5.4
- CVE-2023-3302Improper Neutralization of Formula Elements in a CSV File in admidio/admidio7.8
Product normalization is registry-driven with AI assist and human review. How it works