Known vulnerabilities in Apache Fineract

Software CPE: cpe:2.3:a:apache_foundation:fineract:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Fineract Apache Fineract is affected by 15 known vulnerabilities: 10 medium, 5 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145205 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-57821
CWE-89 Medium
No
No
1.15.0 25.08.2026 SB2026082564
#VU145204 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-35152
CWE-89 Low
No
No
1.15.0 25.08.2026 SB2026082564
#VU145203 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-56287
CWE-89 Low
No
No
1.15.0 25.08.2026 SB2026082564
#VU120249 - Insufficiently Protected Credentials
CVE-2025-58130
CWE-522 Low
No
No
1.12.1 23.12.2025 SB2025122304
#VU120248 - Weak Password Requirements
CVE-2025-23408
CWE-521 Medium
No
No
1.11.0 23.12.2025 SB2025122303
#VU120247 - Authorization Bypass Through User-Controlled Key
CVE-2025-58137
CWE-639 Low
No
No
1.12.1 23.12.2025 SB2025122304
#VU87939 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-23539
CWE-89 Medium
No
No
1.9.0 01.04.2024 SB2024040141
#VU87938 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-23538
CWE-89 Medium
No
No
1.9.0 01.04.2024 SB2024040141
#VU87937 - Permissions, Privileges, and Access Controls
CVE-2024-23537
CWE-264 Medium
No
No
1.9.0 01.04.2024 SB2024040141
#VU86012 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-25197
CWE-89 Medium
No
No
1.8.3 01.02.2024 SB2023032766
#VU86011 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-25196
CWE-89 Medium
No
No
1.8.3 01.02.2024 SB2023032766
#VU86010 - Server-Side Request Forgery (SSRF)
CVE-2023-25195
CWE-918 Medium
No
No
1.7.3, 1.8.4 01.02.2024 SB2023032767
#VU69695 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-44635
CWE-22 Low
No
No
1.8.1 29.11.2022 SB2022112937
#VU53638 - Improper Validation of Certificate with Host Mismatch
CVE-2020-17514
CWE-297 Medium
No
No
1.5.0 28.05.2021 SB2021052802
#VU47649 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20243
CWE-200 Medium
No
No
1.4.0 13.10.2020 SB2020101502