VulnSea

poweradmin/poweradmin vulnerabilities

CVEs whose affected-version data names the poweradmin/poweradmin package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-54588Critical· 9.6
1mo ago

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.

Midnightpoweradmin · poweradmin/poweradminEPSS 0.54%via GHSA
GHSA-h4hf-v6w5-897xHigh· 8.8
2mo ago

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account

Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-rm67-g9ch-vxffHigh· 8.1
2mo ago

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own

Twilightpoweradmin · poweradmin/poweradminvia GHSA
GHSA-cmwh-g2h8-c222High· 8.1
2mo ago

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover

Twilightpoweradmin · poweradmin/poweradminvia GHSA
CVE-2026-47693Medium· 6.9
3mo ago

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications

Sunlitpoweradmin · poweradmin/poweradminEPSS 0.38%via GHSA
poweradmin/poweradmin vulnerabilities (CVEs) · VulnSea