VendorsApachefineractany version
Vulnerabilities

Apache Fineract any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2024-23538
Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published 2024-03-29 · Modified
9.9EPSS 0.013
CVE-2018-11801
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on a m_center data related table.
Published 2019-06-11 · Modified
9.8EPSS 0.052
CVE-2018-11800
SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on the GroupSummaryCounts related table.
Published 2019-06-11 · Modified
9.8EPSS 0.052
CVE-2024-23539
Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries.
Published 2024-03-29 · Modified
9.8EPSS 0.015
CVE-2024-32838
Apache Fineract: SQL injection vulnerabilities in offices API endpoint
Published 2025-02-12 · Analyzed
9.4EPSS 0.015
CVE-2025-58130
Apache Fineract: Server Key not masked
Published 2025-12-12 · Analyzed
9.1EPSS 0.004
CVE-2022-44635
Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal
Published 2022-11-29 · Modified
8.8EPSS 0.688
CVE-2026-35152
Apache Fineract: SQL injection in runreports endpoint
Published 2026-07-15 · Analyzed
8.8EPSS 0.033
CVE-2024-23537
Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role.
Published 2024-03-29 · Modified
8.8EPSS 0.011
CVE-2025-23408
Apache Fineract: weak password policy
Published 2025-12-12 · Analyzed
8.5EPSS 0.005
CVE-2023-25195
Apache Fineract: SSRF template type vulnerability in certain authenticated users
Published 2023-03-28 · Modified
8.1EPSS 0.010
CVE-2026-57821
Apache Fineract: Office list: SQL Injection via Subquery in orderBy
Published 2026-07-15 · Analyzed
8.1EPSS 0.007
CVE-2026-56287
Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure
Published 2026-07-15 · Analyzed
8.1EPSS 0.007
CVE-2025-58137
Apache Fineract: IDOR via self-service API
Published 2025-12-12 · Analyzed
8.1EPSS 0.004
CVE-2018-20243
The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629.
Published 2020-10-13 · Modified
7.5EPSS 0.027
CVE-2020-17514
disabled hostname verificiation
Published 2021-05-27 · Modified
7.4EPSS 0.034
CVE-2023-25197
apache fineract: SQL injection vulnerability in certain procedure calls
Published 2023-03-28 · Modified
6.3EPSS 0.011
CVE-2023-25196
Apache Fineract: SQL injection vulnerability
Published 2023-03-28 · Modified
4.3EPSS 0.013