VulnSea

admin3 vulnerabilities

CVEs whose affected-version data names the admin3 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-92921Medium· 4.9PoC
6d ago

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force …

Twilightcjbi · admin3EPSS 0.18%via NVD
CVE-2026-92920Medium· 5.4
6d ago

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…

Sunlitcjbi · admin3EPSS 0.18%via NVD
CVE-2026-92919High· 8.1PoC
6d ago

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …

Midnightcjbi · admin3EPSS 0.38%via NVD
CVE-2026-92918High· 8.8PoC
6d ago

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens…

Midnightcjbi · admin3EPSS 0.35%via NVD
admin3 vulnerabilities (CVEs) · VulnSea