These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T15:16:46.747Z and has not been modified since then. The vulnerability exists in Admidio versions before 5.0.12, allowing authenticated low-privilege users to bypass profile-level authorization and read another user's future role memberships by directly calling the reload_future_memberships endpoi [truncated]
The Admidio application before version 5.0.12 has an authentication bypass vulnerability in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps. This vulnerability allows unauthorized access to sensitive [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T15:16:46.310Z and has not been modified since then. CVE-2026-82655 is a blind SQL injection vulnerability in Admidio versions prior to 5.0.12. The vulnerability exists in the lists_show.php file, specifically in the relation_type_list parameter, allowing unauthenticated attackers to execute arbit [truncated]
CVE-2026-47234 Admidio debug log credential exposure. Admidio versions prior to 5.0.10 have a vulnerability that exposes sensitive session cookie values in logs when debug logging is enabled. This issue allows potential exposure of live bearer-style credentials in logs. The vulnerability is fixed in version 5.0.10. Admidio users and administrators should assess their exposure, verify logging configuration [truncated]
CVE-2026-47233 is a vulnerability in Admidio, an open-source user management solution. The vulnerability was introduced in version 5.0.9 and fixed in version 5.0.10. It allows any logged-in user to permanently delete a non-system inventory field by sending a POST request, due to a missing access control check. This could lead to data loss and unauthorized changes. Administrators should assess their exposu [truncated]
A vulnerability in Admidio, a user management solution, allows for the export of a private key and certificate without a valid form token due to a commented-out CSRF validation line. This issue exists in versions prior to 5.0.10. Administrators of Admidio instances should assess their exposure, verify their version, and consider upgrading to version 5.0.10 to mitigate potential security risks associated w [truncated]
CVE-2026-47231 is a high-severity vulnerability in Admidio, an open-source user management solution. The vulnerability allows any user who can upload to any single folder to move any file from any other folder, including private folders to which they have no view rights, into a folder they control, and then download it. This breaks confidentiality and integrity, as private file contents leak and the file [truncated]
A vulnerability in Admidio, a user management solution, allows users with upload rights in one folder to rename and overwrite files in another folder they can view but not upload to. This issue, fixed in version 5.0.10, highlights the need for stricter access controls and monitoring of file operations. The vulnerability exists due to inadequate checks in the `modules/documents-files.php` file, specificall [truncated]
CVE-2026-47229 is a vulnerability in Admidio, an open-source user management solution, prior to version 5.0.10. The issue lies in the `modules/sso/clients.php` file, where the `adm_csrf_token` is not validated on the `enable` branch. This allows a third-party page to trick an authenticated administrator into disabling or re-enabling any configured SAML or OIDC client via plain GET parameters. Disabling an [truncated]
CVE-2026-47228 is a vulnerability in Admidio's user management solution. The `modules/registration.php` file has a mode `send_login` that regenerates a random password for a user and emails it in cleartext without validating a CSRF token. This allows an attacker to reset a user's password if the request is issued as a top-level navigation by a registration-administrator. The issue was fixed in version 5.0.10.
CVE-2026-47227 is a vulnerability in Admidio, an open-source user management solution. The issue allows a user with administrator rights to one module to delete, reorder, or save categories belonging to other modules they do not administer. This is possible due to a dead code check in `modules/categories.php` that prevents the `isEditable()` method from being invoked. The vulnerability was fixed in version 5.0.10.
CVE-2026-47226 is a vulnerability in Admidio, an open-source user management solution, where an authenticated member with upload rights on any one folder can permanently delete files from folders where they have only view access. The issue arises from an incomplete authorization check in the `modules/documents-files.php` file, allowing attackers to bypass upload-right checks and delete files. This vulnera [truncated]
CVE-2026-69094 is an insecure direct object reference vulnerability in Admidio versions before 5.0.11. The vulnerability allows authenticated users to hijack list configurations by enumerating global list UUIDs and overwriting admin-curated global lists or other users' private lists. This can lead to unauthorized access and modification of sensitive information. Defenders should assess the vulnerability a [truncated]
CVE-2026-69093 is a high-severity vulnerability in Admidio versions before 5.0.11. The issue arises from the lack of validation for the `adm_csrf_token` in `modules/category-report/preferences.php`, allowing an attacker to trick an authenticated administrator into visiting a crafted URL. This can lead to the deletion or duplication of Category Report configurations, affecting the integrity and availabilit [truncated]
CVE-2026-69092 is a reflected cross-site scripting vulnerability affecting Admidio versions before 5.0.11. The vulnerability is located in the SSO/SAML endpoint and allows unauthenticated attackers to inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters. This can lead to code execution in users' browsers and session hijacking.
CVE-2026-69091 is an authentication bypass vulnerability in Admidio before 5.0.11. The vulnerability exists in the forum module when configured in login-only mode. The access control logic fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts. This vulnerability has a high CVSS score of 8.7 and is considered a significant risk. Defenders sh [truncated]
CVE-2026-69090 is a vulnerability in Admidio before version 5.0.11, where authenticated role administrators can delete, activate, deactivate, or edit roles belonging to other organizations due to a failure in validating target organization membership in role handlers. This issue allows attackers to supply a role UUID from another organization to groups_roles.php handlers to modify that organization's role [truncated]
CVE-2018-25370 documents a cross-site request forgery (CSRF) vulnerability in Admidio 3.3.5 that enables low-privilege users to escalate their permissions. The flaw resides in improper origin checking within roles_function.php, allowing attackers to craft malicious HTML forms that set role parameters (rol_assign_roles, rol_approve_users, rol_edit_user) to 1 without requiring authentication. The vulnerabil [truncated]
CVE-2026-34384 is a vulnerability in Admidio, an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. This allows an attacker who has submitted a pending registration to trick any user with the rol_approve_users right into vis [truncated]
CVE-2026-34382 is a medium-severity vulnerability affecting Admidio, an open-source user management solution, versions 5.0.0 through 5.0.7. The vulnerability allows an attacker to permanently delete list configurations without proper CSRF validation, potentially impacting organization-wide shared lists if an administrator is tricked into visiting a malicious page. This issue has significant implications f [truncated]
CVE-2026-34381 is a high-severity vulnerability in Admidio versions 5.0.0 to 5.0.7. The issue arises from Admidio's reliance on .htaccess to restrict direct HTTP access to uploaded documents. However, the Docker image is configured with 'AllowOverride None' in Apache, causing .htaccess files to be ignored. Consequently, files uploaded to the documents module can be accessed directly via HTTP without authe [truncated]
CVE-2017-6492 describes a SQL injection vulnerability in Admidio 3.2.5 affecting the dates_function.php code path. The issue is caused by concatenating the POST parameter dat_cat_id directly into a SQL query without input validation or sanitization. NVD rates the issue as CVSS 3.0 7.2 (HIGH) and maps it to CWE-89.