Funadmin is a narrowly scoped administrative application that occupies a prominent position in vulnerability disclosures despite limited product breadth, suggesting significant deployment in environments where administrative access is critical. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across a consistent attack surface: SQL injection, cross-site scripting, code injection, and deserialization of untrusted data—all application-layer input-handling and execution flaws that reflect the direct exposure of web-based administrative functionality. The concentration of critical issues in a single, widely used administrative product creates outsized risk for organizations deploying it, as a single flaw may grant direct control over managed systems. Defenders should prioritize this vendor's advisories and ensure administrative instances are isolated, patched expeditiously, and protected from untrusted network access; live exploitation activity, severity details, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Funadmin over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24775CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php. | Mar 7, 2023 | 9.8 | 39 | NO | NO |
CVE-2023-24774CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. | Mar 10, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24777CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24782CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24773CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24780CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns. | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24781CRITICAL Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php. | Mar 7, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-24776CRITICAL Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. | Mar 6, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-2894CRITICAL A vulnerability was identified in funadmin up to 7.1.0-rc4. Affected by this vulnerability is the function getMember of the file app/frontend/view/login/forget.html. Such manipulat | Feb 21, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-2896HIGH A weakness has been identified in funadmin up to 7.1.0-rc4. This affects the function setConfig of the file app/backend/controller/Ajax.php of the component Configuration Handler. | Feb 22, 2026 | 7.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Funadmin.
Media articles that mention a CVE ID that affects a product developed by Funadmin — matched by CVE ID, not by vendor name.