Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Eladmin

First CVE: Aug 4, 2024Active for: 2 yearsTotal CVEs: 15
31.7
VTI Score
Medium

Eladmin is a modestly represented backend-administration framework whose vulnerability profile concentrates in a single product yet ranks among the more prominent vendors in the landscape, likely reflecting its use as a foundational component across multiple deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes including untrusted deserialization, improper access control and authorization, input validation gaps, and injection flaws that are characteristic of web-administration platforms handling privileged operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Eladmin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 4, 2024
23 months ago
Most Recent CVE
Feb 4, 2026
170 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-7458CRITICAL
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of
Aug 4, 20249.827NONO
CVE-2024-44677CRITICAL
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
Sep 10, 20249.826NONO
CVE-2025-22978CRITICAL
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
Feb 3, 20259.825NONO
CVE-2025-9241HIGH
A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The
Aug 20, 20257.524NONO
CVE-2025-8530HIGH
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is some unknown functionality of the file eladmin-system\sr
Aug 4, 20257.522NONO
CVE-2024-51243HIGH
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.
Oct 30, 20247.221NONO
CVE-2025-70997MEDIUM
A vulnerability has been discovered in eladmin v2.7 and before. This vulnerability allows for an arbitrary user password reset under any user permission level.
Feb 4, 20266.520NONO
CVE-2025-3250MEDIUM
A vulnerability, which was classified as problematic, has been found in elunez eladmin 2.7. Affected by this issue is some unknown functionality of the file /api/database/testConne
Apr 4, 20256.520NONO
CVE-2025-2855HIGH
A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. T
Mar 27, 20257.220NONO
CVE-2024-51242MEDIUM
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter lea
Oct 30, 20246.519NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
13%
40%
27%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None14 (93.3%)
Unknown0 (0.0%)
Required1 (6.7%)
Privileges Required
Low4 (26.7%)
High4 (26.7%)
None7 (46.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Eladmin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Eladmin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Eladmin's Products

View all 2 CNAs →

Top CWEs