Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Admidio

First CVE: Nov 24, 2008Active for: 18 yearsTotal CVEs: 32
41.8
VTI Score
High

Admidio is a volunteer and member management platform with a narrowly scoped product portfolio centered on a single core application, deployed across organizations requiring administration and community tools. The vendor's vulnerability disclosures cluster around web-application layer weaknesses including cross-site request forgery, cross-site scripting, SQL injection, unrestricted file uploads, and improper access control—a characteristic pattern for web-facing management platforms where input handling and privilege boundaries are critical. Vulnerabilities affecting this vendor show a moderate tendency toward public exploit availability, reflecting the relative accessibility of web-application attack surface to researchers and tooling. Defenders managing Admidio installations should prioritize patching releases for these web-oriented weakness classes and restrict administrative access paths; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
3.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Admidio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2008
17 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-43810MEDIUM
Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. T
Dec 7, 20216.133NOYES
CVE-2026-32817CRITICAL
Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delet
Mar 20, 20269.130NONO
CVE-2026-32756HIGH
Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a des
Mar 20, 20268.828NONO
CVE-2024-38529HIGH
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in
Jul 29, 20248.827NONO
CVE-2017-8382MEDIUM
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.
May 16, 20174.527NOYES
CVE-2026-34381HIGH
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded docu
Mar 31, 20267.526NONO
CVE-2026-32813HIGH
Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configur
Mar 20, 20268.026NONO
CVE-2021-32630HIGH
Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload
May 20, 20218.826NONO
CVE-2025-62617HIGH
Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionali
Oct 22, 20257.224NONO
CVE-2020-11004HIGH
SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacke
Apr 24, 20207.524NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
50%
41%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.1%)
Network30 (93.8%)
Unknown1 (3.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (96.9%)
High0 (0.0%)
Unknown1 (3.1%)
User Interaction
None16 (50.0%)
Unknown1 (3.1%)
Required15 (46.9%)
Privileges Required
Low18 (56.3%)
High5 (15.6%)
None8 (25.0%)
Unknown1 (3.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.1% of CVEs· 95th percentile
ExploitDB
2 CVEs
6.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Admidio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Admidio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Admidio's Products

View all 3 CNAs →

Top CWEs