Skip to main content

Vendor/product archive

apache / fineract CVEs

Beta · best-effort

23 CVEs tagged to apache / fineract6 Critical, 15 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-57821

Published Jul 15, 2026

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concaten…

CVSS 8.1 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-56287

Published Jul 15, 2026

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder r…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-35152

Published Jul 15, 2026

A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to and including 1.14.0. Report parameter values are incorporat…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-58137

Published Dec 12, 2025

Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. User…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58130

Published Dec 12, 2025

Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encour…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-23408

Published Dec 12, 2025

Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0. Users are encouraged to up…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32838

Published Feb 12, 2025

SQL Injection vulnerability in various API endpoints - offices, dashboards, etc. Apache Fineract versions 1.9 and before have a vulnerability that allows an authenticated attacker…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-23539

Published Mar 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recomm…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23538

Published Mar 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recomm…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-23537

Published Mar 29, 2024

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issu…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25197

Published Mar 28, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to e…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25196

Published Mar 28, 2023

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract. Authorized users may be able to c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25195

Published Mar 28, 2023

Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44635

Published Nov 29, 2022

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an att…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17514

Published May 27, 2021

Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under typical deployments, a man in the middle attack could b…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20243

Published Oct 13, 2020

The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11801

Published Jun 11, 2019

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11800

Published Jun 11, 2019

SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1292

Published Apr 20, 2018

Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn'…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1291

Published Apr 20, 2018

Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' wh…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1290

Published Apr 20, 2018

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injecti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1289

Published Apr 20, 2018

In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Quer…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5663

Published Dec 14, 2017

In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1