Home/Product/fastadmin
Product

fastadmin

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-14966
<= 1.6.1.20250430
A vulnerability was determined in FastAdmin up to 1.7.0.20250506. Affected is the function selectpage of the file application/comm
4.7MEDIUM
CVE-2024-7928
< 1.3.4.20220530
A vulnerability, which was classified as problematic, has been found in FastAdmin up to 1.3.3.20220121. Affected by this issue is
4.3MEDIUM
CVE-2024-7453
all versions
A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown cod
2.4LOW
CVE-2021-43117
all versions
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
9.8CRITICAL
CVE-2020-26609
all versions
fastadmin V1.0.0.20200506_beta contains a cross-site scripting (XSS) vulnerability which may allow an attacker to obtain administr
5.4MEDIUM
CVE-2020-25967
all versions
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerabilit
8.8HIGH
CVE-2020-21665
all versions
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQ
7.2HIGH
CVE-2019-17432
all versions
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability, as demon
6.5MEDIUM
CVE-2019-17431
all versions
An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerability.
8.8HIGH
CVE-2019-11077
all versions
FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 URI.
8.8HIGH
CVE-2018-10268
all versions
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar paramet
5.4MEDIUM
threatengine.sh