Admidio is a volunteer and member management platform with a narrowly scoped product portfolio centered on a single core application, deployed across organizations requiring administration and community tools. The vendor's vulnerability disclosures cluster around web-application layer weaknesses including cross-site request forgery, cross-site scripting, SQL injection, unrestricted file uploads, and improper access control—a characteristic pattern for web-facing management platforms where input handling and privilege boundaries are critical. Vulnerabilities affecting this vendor show a moderate tendency toward public exploit availability, reflecting the relative accessibility of web-application attack surface to researchers and tooling. Defenders managing Admidio installations should prioritize patching releases for these web-oriented weakness classes and restrict administrative access paths; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Admidio over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43810MEDIUM Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. T | Dec 7, 2021 | 6.1 | 33 | NO | YES |
CVE-2026-32817CRITICAL Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the documents and files module does not verify whether the current user has permission to delet | Mar 20, 2026 | 9.1 | 30 | NO | NO |
CVE-2026-32756HIGH Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a des | Mar 20, 2026 | 8.8 | 28 | NO | NO |
CVE-2024-38529HIGH Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in | Jul 29, 2024 | 8.8 | 27 | NO | NO |
CVE-2017-8382MEDIUM admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts. | May 16, 2017 | 4.5 | 27 | NO | YES |
CVE-2026-34381HIGH Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my_files/.htaccess to deny direct HTTP access to uploaded docu | Mar 31, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-32813HIGH Admidio is an open-source user management solution. Versions 5.0.6 and below are vulnerable to arbitrary SQL Injection through the MyList configuration feature. The MyList configur | Mar 20, 2026 | 8.0 | 26 | NO | NO |
CVE-2021-32630HIGH Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.0.4, there is an authenticated RCE via .phar file upload | May 20, 2021 | 8.8 | 26 | NO | NO |
CVE-2025-62617HIGH Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerability exists in the member assignment data retrieval functionali | Oct 22, 2025 | 7.2 | 24 | NO | NO |
CVE-2020-11004HIGH SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacke | Apr 24, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Admidio.
Media articles that mention a CVE ID that affects a product developed by Admidio — matched by CVE ID, not by vendor name.