Pearadmin maintains a narrow portfolio of web-based administration frameworks and dashboard products that handle user input and file upload handling, presenting a focused but meaningful attack surface in application layer security. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur across products such as Pear Admin Boot and Pear Admin Think through characteristic web-application weakness classes including SQL injection, cross-site scripting, and unrestricted file upload. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pearadmin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-29377CRITICAL Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/ | Aug 12, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-6241CRITICAL A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function getDictItems of the file /system/dictData/getDictItems/. The ma | Jun 21, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-6266CRITICAL A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of the file /system/dictData/loadDictItem. The manipulation le | Jun 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2021-29378HIGH SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php. | Aug 11, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-30417MEDIUM A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title o | Apr 25, 2023 | 5.4 | 19 | NO | NO |
CVE-2022-23903MEDIUM A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to access arbitrary functions and cause stored XSS through a f | Mar 29, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pearadmin.
Media articles that mention a CVE ID that affects a product developed by Pearadmin — matched by CVE ID, not by vendor name.