poweradmin/poweradmin vulnerabilities
CVEs whose affected-version data names the poweradmin/poweradmin package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-54588Critical· 9.6Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
▾ Midnightpoweradmin · poweradmin/poweradminEPSS 0.54%via GHSA
GHSA-h4hf-v6w5-897xHigh· 8.8Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-rm67-g9ch-vxffHigh· 8.1Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-cmwh-g2h8-c222High· 8.1Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover
▾ Twilightpoweradmin · poweradmin/poweradminvia GHSA
CVE-2026-47693Medium· 6.9Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
▾ Sunlitpoweradmin · poweradmin/poweradminEPSS 0.38%via GHSA