Admin
This hub aggregates every CVE we track for Admin, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM8LOW1HIGH1
Monthly trend
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
2
0
0
0
2024-082026-07
Latest CVEs
The 10 most recently published vulnerabilities affecting Admin.
- CVE-2026-5252z-9527 admin Message Create Endpoint message.js cross site scripting3.5
- CVE-2026-5251z-9527 admin User Update Endpoint user.js dynamically-determined object attributes6.3
- CVE-2026-4999z-9527 admin isImg Check upload.js uploadFile path traversal6.3
- CVE-2026-3200z-9527 admin user.js getUsers sql injection7.3
- CVE-2024-8155ContiNew Admin tree sql injection4.7
- CVE-2024-8150ContiNew Admin user sql injection4.7
- CVE-2023-49783No permission checks for editing/deleting records with CSV import form4.3
- CVE-2023-46754The admin panel for Obl.ong before 1.1.2 allows authorization bypass because the email OTP feature accepts arbitrary numerical values.5.3
- CVE-2012-1631Cross-site request forgery (CSRF) vulnerability in the Admin:hover module for Drupal allows remote attackers to hijack the authentication of administrators for requests that unpublish all nodes, an...6.8
- CVE-2007-6232Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter in an error page action.4.3
Product normalization is registry-driven with AI assist and human review. How it works