Apache Fineract vulnerabilities
23 known vulnerabilities affecting apache/fineract.
Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM3
Vulnerabilities
Page 2 of 2
CVE-2025-23408P3MEDIUMCVSS 6.5fixed in 1.11.02025-12-12
CVE-2025-23408 [MEDIUM] CWE-521 CVE-2025-23408: Weak Password Requirements vulnerability in Apache Fineract. This issue affects Apache Fineract: th
Weak Password Requirements vulnerability in Apache Fineract.
This issue affects Apache Fineract: through 1.10.1. The issue is fixed in version 1.11.0.
Users are encouraged to upgrade to version 1.13.0, the latest release.
nvd
CVE-2023-25197P3MEDIUMCVSS 6.3≥ 1.4.0, ≤ 1.8.22023-03-28
CVE-2023-25197 [MEDIUM] CWE-89 CVE-2023-25197: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract.
Authorized users may be able to exploit this for limited impact on components.
This issue affects apache fineract: from 1.4 through 1.8.2.
nvd
CVE-2023-25196P4MEDIUMCVSS 4.3≥ 1.4.0, ≤ 1.8.22023-03-28
CVE-2023-25196 [MEDIUM] CWE-89 CVE-2023-25196: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache Fineract.
Authorized users may be able to change or add data in certain components.
This issue affects Apache Fineract: from 1.4 through 1.8.2.
nvd
← Previous2 / 2