Fastadmin is a web-based administrative framework with a concentrated vulnerability footprint centered on input validation and output-encoding weaknesses characteristic of server-side templating and database integration. The recurring exposure spans cross-site scripting, cross-site request forgery, SQL injection, path traversal, and related injection classes that reflect the framework's role handling user input across web forms and backend queries. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastadmin over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7928HIGH A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is some unknown functionality of the file /index/ajax | Aug 19, 2024 | 7.5 | 44 | NO | YES |
CVE-2021-43117CRITICAL fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access. | Dec 13, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-17431HIGH An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability. | Oct 10, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-11077HIGH FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI. | Apr 11, 2019 | 8.8 | 27 | NO | NO |
CVE-2020-25967HIGH The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability. | Dec 10, 2020 | 8.8 | 26 | NO | NO |
CVE-2025-14966HIGH A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/common/controller/Backend.php of the component Backend | Dec 19, 2025 | 7.2 | 24 | NO | NO |
CVE-2019-17432MEDIUM An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demonstrated by resultant XSS via the row[name] | Oct 10, 2019 | 6.5 | 21 | NO | NO |
CVE-2020-26609MEDIUM fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administrator credentials to log in to the background. | Feb 23, 2021 | 5.4 | 19 | NO | NO |
CVE-2020-21665HIGH In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh. | Nov 17, 2020 | 7.2 | 19 | NO | NO |
CVE-2018-10268MEDIUM An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter. | Apr 22, 2018 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastadmin.
Media articles that mention a CVE ID that affects a product developed by Fastadmin — matched by CVE ID, not by vendor name.