Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-3735-5339-xfwx
  • Packagist/poweradmin/poweradmin
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. 28 Jul
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-cmwh-g2h8-c222
  • Packagist/poweradmin/poweradmin
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover 24 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-rm67-g9ch-vxff
  • Packagist/poweradmin/poweradmin
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own 24 Jul
  • Fix available
  • Severity - 8.1 (High)
GHSA-h4hf-v6w5-897x
  • Packagist/poweradmin/poweradmin
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account 24 Jul
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-54588
  • github.com/poweradmin/poweradmin
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. 23 Jun
  • Fix available
  • Severity - 9.6 (Critical)
CVE-2026-47693
  • github.com/poweradmin/poweradmin
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications 23 Jun
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-3h6h-67x3-cv5x
  • Packagist/poweradmin/poweradmin
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications 08 Jun
  • Fix available
  • Severity - 6.9 (Medium)