Szadmin develops the Sz Boot Parent product, a narrowly scoped offering where the durable vulnerability signal centers on access-control and authentication weaknesses including authorization bypass through user-controlled keys, improper access control, improper authorization, unrestricted file uploads, and use of default passwords. These weakness patterns reflect typical risks in administrative and bootstrap-layer software where credential management and input validation are critical to security posture. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Szadmin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3187CRITICAL A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the c | Feb 25, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-3186MEDIUM A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/pas | Feb 25, 2026 | 6.3 | 20 | NO | NO |
CVE-2026-3185MEDIUM A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The ma | Feb 25, 2026 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Szadmin.
Media articles that mention a CVE ID that affects a product developed by Szadmin — matched by CVE ID, not by vendor name.