CVE Tools

Funadmin

16 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

Funadmin CVEs per month

Oct 2024 to Feb 2026. Point at a month, or focus the strip and use the arrow keys.
Funadmin CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-10110
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-0250

Products

The products that kept showing up in Funadmin's monthly top three, with their CVEs summed over those months.

  1. Funadmin162 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Funadmin.

  1. CVE-2026-2898funadmin Backend Endpoint AuthCloudService.php getMember deserialization5.5
  2. CVE-2026-2897funadmin Backend index.html cross site scripting2.4
  3. CVE-2026-2896funadmin Configuration Ajax.php setConfig improper authorization7.3
  4. CVE-2026-2895funadmin Member.php repass password recovery3.7
  5. CVE-2026-2894funadmin forget.html getMember information disclosure5.3
  6. CVE-2024-48225Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile.6.5
  7. CVE-2024-48229funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.7.2
  8. CVE-2024-48218Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.7.2
  9. CVE-2024-48230funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.7.2
  10. CVE-2024-48223Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.7.2
  11. CVE-2024-48226Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.7.2
  12. CVE-2024-48227Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS).4.9
  13. CVE-2024-48224Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.4.9
  14. CVE-2024-48222Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.7.2
  15. CVE-2024-48228An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resu...6.1

The record

Peak rank
#61 in Oct 2024
Busiest month shown
Oct 2024, 11 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
2 since 2024
Funadmin's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store