Eladmin is a modestly represented backend-administration framework whose vulnerability profile concentrates in a single product yet ranks among the more prominent vendors in the landscape, likely reflecting its use as a foundational component across multiple deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including untrusted deserialization, improper access control and authorization, input validation gaps, and injection flaws that are characteristic of web-administration platforms handling privileged operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eladmin over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7458CRITICAL A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of | Aug 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-44677CRITICAL eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component. | Sep 10, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-22978CRITICAL eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module. | Feb 3, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-9241HIGH A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The | Aug 20, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-8530HIGH A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\sr | Aug 4, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-51243HIGH The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController. | Oct 30, 2024 | 7.2 | 21 | NO | NO |
CVE-2025-70997MEDIUM A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permission level. | Feb 4, 2026 | 6.5 | 20 | NO | NO |
CVE-2025-3250MEDIUM A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConne | Apr 4, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-2855HIGH A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. T | Mar 27, 2025 | 7.2 | 20 | NO | NO |
CVE-2024-51242MEDIUM A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter lea | Oct 30, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eladmin.
Media articles that mention a CVE ID that affects a product developed by Eladmin — matched by CVE ID, not by vendor name.