Funadmin Vulnerabilities

Comprehensive security vulnerability database for Funadmin products

Last updated: Feb 22, 2026
Total CVEs

5

Critical

0

With Exploits

5

Last 30 Days

0

Severity Distribution

Critical0
0%
High0
0%
Medium5
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-28985.1

An attacker can remotely exploit a vulnerability in funadmin to manipulate user account data, potentially allowing them to execute harmful code on the server. This issue affects versions up to 7.1.0-rc4 and arises from improper handling of input in the authentication service.

funadminfunadmin
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-28974.8

This vulnerability allows an attacker to inject malicious scripts into the backend interface of the funadmin application, potentially compromising user data or session information. It can be exploited remotely without needing special access, making it a significant risk for users running affected versions up to 7.1.0-rc4.

funadminfunadmin
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-28966.9

An attacker can remotely manipulate the configuration settings of the funadmin software, potentially allowing them to gain unauthorized access to sensitive features or data. This vulnerability affects versions up to 7.1.0-rc4, and it has been publicly disclosed, meaning that anyone can exploit it if they know how.

funadminfunadmin
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-28956.3

An attacker can exploit a weakness in the password recovery process of funadmin to potentially reset user passwords and gain unauthorized access to accounts. This requires the attacker to manipulate specific recovery codes, and while the method is complex and difficult, public information about the exploit is now available, increasing the risk of attacks.

funadminfunadmin
Exploit Available
about 1 month agoFeb 21, 2026
CVE-2026-28945.5

This vulnerability allows an attacker to remotely access sensitive information from the funadmin application, specifically through a function related to password recovery. The issue affects versions up to 7.1.0-rc4, and there is already a publicly available exploit that could be used to take advantage of this flaw.

funadminfunadmin
Exploit Available
about 1 month agoFeb 21, 2026

About Funadmin Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Funadmin products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.