Continew's vulnerability profile is concentrated in its administrative application, which presents a modestly scoped but prominently positioned management interface. The exposure recurs through application-layer input-handling and authentication-control weaknesses, including SQL injection, code injection, cross-site scripting, server-side request forgery, and unverified password-change conditions that are characteristic of web-facing administrative tools. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Continew over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3750HIGH A security vulnerability has been detected in ContiNew Admin up to 4.2.0. This issue affects the function URI.create of the file continew-system/src/main/java/top/continew/admin/sy | Mar 8, 2026 | 7.2 | 22 | NO | NO |
CVE-2025-4552HIGH A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/u | May 12, 2025 | 8.1 | 20 | NO | NO |
CVE-2024-8155MEDIUM A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseControll | Aug 25, 2024 | 4.9 | 19 | NO | NO |
CVE-2024-8150MEDIUM A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#p | Aug 25, 2024 | 4.9 | 18 | NO | NO |
CVE-2025-4551MEDIUM A vulnerability, which was classified as problematic, was found in ContiNew Admin up to 3.6.0. Affected is an unknown function of the file /dev-api/common/file. The manipulation of | May 11, 2025 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Continew.
Media articles that mention a CVE ID that affects a product developed by Continew — matched by CVE ID, not by vendor name.