CVE-2026-34383Medium· 4.3▾ SunlitAdmidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user can craft a direct POST request to save arbitrary inventory item data without CSRF protection and without the field value checks that the FormPresenter validation normally enforces. This issue has been patched in version 5.0.8.
admidio < 5.0.8Upgrade past the affected range:
admidio 5.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34384Medium· 4.5Admidio is an open-source user management solution
CVE-2026-34382Medium· 4.6Admidio is an open-source user management solution
CVE-2026-53760Medium· 5.2Admidio is an open-source user management solution
CVE-2026-34381High· 7.5Admidio is an open-source user management solution
CVE-2026-47230Medium· 6.5Admidio is an open-source user management solution
CVE-2026-47227Medium· 6.5Admidio is an open-source user management solution