CVE-2026-32813 is a high-severity second-order SQL Injection vulnerability impacting Admidio versions 5.0.6 and below. This flaw allows authenticated users to inject arbitrary SQL commands through the MyList configuration feature, where user-supplied data is unsafely interpolated into dynamic SQL queries. Rated 8.0 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H), successful exploitation can lead to full database compromise, including reading, modifying, or deleting any data. While it requires user interaction for exploitation, the attack complexity is low. There is currently no public exploit code, nor evidence of active exploitation or significant community discussion. The vulnerability has been addressed in Admidio version 5.0.7.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.7CPE matchmatch criteria | cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.