Bearadmin Project maintains a narrowly scoped administrative interface product where the durable exposure pattern centers on web-application input-handling and file-upload controls, including path traversal, SQL injection, and unrestricted file upload weaknesses. Treat this as a compact vendor profile rather than a trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bearadmin Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35261CRITICAL File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of t | Feb 17, 2023 | 9.8 | 29 | NO | NO |
CVE-2018-11414HIGH An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly. | May 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-11413MEDIUM An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by na | May 24, 2018 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bearadmin Project.
Media articles that mention a CVE ID that affects a product developed by Bearadmin Project — matched by CVE ID, not by vendor name.