VendorsApachefineractall versions
Vulnerabilities

Apache Fineract

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2024-23538
Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published 2024-03-29 · Modified
9.9EPSS 0.013
CVE-2018-11801
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
Published 2019-06-11 · Modified
9.8EPSS 0.052
CVE-2018-11800
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.
Published 2019-06-11 · Modified
9.8EPSS 0.052
CVE-2018-1290
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, Using a single quotation escape with two continuous SQL parameters can cause a SQL injection. This could be done in Methods like retrieveAuditEntries of AuditsApiResource Class and retrieveCommands of MakercheckersApiResource Class.
Published 2018-04-20 · Modified
9.8EPSS 0.033
CVE-2024-23539
Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published 2024-03-29 · Modified
9.8EPSS 0.015
CVE-2024-32838
Apache Fineract: SQL injection vulnerabilities in offices API endpoint
Published 2025-02-12 · Analyzed
9.4EPSS 0.015
CVE-2025-58130
Apache Fineract: Server Key not masked
Published 2025-12-12 · Analyzed
9.1EPSS 0.004
CVE-2022-44635
Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal
Published 2022-11-29 · Modified
8.8EPSS 0.688
CVE-2026-35152
Apache Fineract: SQL injection in runreports endpoint
Published 2026-07-15 · Analyzed
8.8EPSS 0.033
CVE-2018-1289
In Apache Fineract versions 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, the system exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' and 'sortOrder' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' and 'sortOrder' query parameter in such a way to read/update the data for which he doesn't have authorization.
Published 2018-04-20 · Modified
8.8EPSS 0.026
CVE-2017-5663
In Apache Fineract 0.4.0-incubating, 0.5.0-incubating, and 0.6.0-incubating, an authenticated user with client/loan/center/staff/group read permissions is able to inject malicious SQL into SELECT queries. The 'sqlSearch' parameter on a number of endpoints is not sanitized and appended directly to the query.
Published 2017-12-14 · Modified
8.8EPSS 0.021
CVE-2024-23537
Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.
Published 2024-03-29 · Modified
8.8EPSS 0.011
CVE-2025-23408
Apache Fineract: weak password policy
Published 2025-12-12 · Analyzed
8.5EPSS 0.005
CVE-2018-1292
Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker could inject SQL to read/update data for which he doesn't have authorization for by way of the 'reportName' parameter.
Published 2018-04-20 · Modified
8.1EPSS 0.021
CVE-2018-1291
Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain specific entities with a Query Parameter 'orderBy' which are appended directly with SQL statements. A hacker/user can inject/draft the 'orderBy' query parameter by way of the "order" param in such a way to read/update the data for which he doesn't have authorization.
Published 2018-04-20 · Modified
8.1EPSS 0.020
CVE-2023-25195
Apache Fineract: SSRF template type vulnerability in certain authenticated users
Published 2023-03-28 · Modified
8.1EPSS 0.010
CVE-2026-57821
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Published 2026-07-15 · Analyzed
8.1EPSS 0.007
CVE-2026-56287
Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Published 2026-07-15 · Analyzed
8.1EPSS 0.007
CVE-2025-58137
Apache Fineract: IDOR via self-service API
Published 2025-12-12 · Analyzed
8.1EPSS 0.004
CVE-2018-20243
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
Published 2020-10-13 · Modified
7.5EPSS 0.027
CVE-2020-17514
disabled hostname verificiation
Published 2021-05-27 · Modified
7.4EPSS 0.034
CVE-2023-25197
apache fineract: SQL injection vulnerability in certain procedure calls
Published 2023-03-28 · Modified
6.3EPSS 0.011
CVE-2023-25196
Apache Fineract: SQL injection vulnerability
Published 2023-03-28 · Modified
4.3EPSS 0.013