CVE-2026-34382Medium· 4.6▾ SunlitAdmidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can l…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently destroy that user's list configurations — including organization-wide shared lists when the victim holds administrator rights. This issue has been patched in version 5.0.8.
admidio >= 5.0.0, < 5.0.8Upgrade past the affected range:
admidio 5.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34384Medium· 4.5Admidio is an open-source user management solution
CVE-2026-34383Medium· 4.3Admidio is an open-source user management solution
CVE-2026-53760Medium· 5.2Admidio is an open-source user management solution
CVE-2026-34381High· 7.5Admidio is an open-source user management solution
CVE-2026-47230Medium· 6.5Admidio is an open-source user management solution
CVE-2026-47227Medium· 6.5Admidio is an open-source user management solution