frontaccounting
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting frontaccounting.
- CVE-2026-40521FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload8.8
- CVE-2026-40522FrontAccounting < 2.4.20 SQL Injection via rep601.php7.1
- CVE-2026-40523FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php8.1
- CVE-2026-40524FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()8.1
- CVE-2014-125080frontaccounting faplanet path traversal5.5
- CVE-2020-21244An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.4.9
- CVE-2019-5720includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field that can allow the attacker to grab the entire database of the application v...9.8
- CVE-2018-1000890FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the applic...7.5
- CVE-2018-7176FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).8.8
- CVE-2014-3973Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
- CVE-2011-3740FrontAccounting 2.3.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by report...5.0
- CVE-2009-4046Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) ...7.5
- CVE-2009-4045Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1)...7.5
- CVE-2009-4037Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admi...7.5
- CVE-2007-5148Multiple PHP remote file inclusion vulnerabilities in FrontAccounting (FA) 1.12 allow remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter to (1) access/logout.php...6.8