Shabti Kaplan Frontend Admin By Dynamiapps vulnerabilities
7 known vulnerabilities affecting shabti_kaplan/frontend_admin_by_dynamiapps.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-66662P2CRITICALCVSS 9.8≥ n/a, ≤ 3.29.102026-08-06
CVE-2026-66662 [CRITICAL] CWE-266 CVE-2026-66662: Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.
nvd
CVE-2023-51411P3CRITICALCVSS 9.8≥ n/a, ≤ 3.18.32023-12-29
CVE-2023-51411 [CRITICAL] CWE-434 CVE-2023-51411: Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by Dyn
Unrestricted Upload of File with Dangerous Type vulnerability in Shabti Kaplan Frontend Admin by DynamiApps.This issue affects Frontend Admin by DynamiApps: from n/a through 3.18.3.
nvd
CVE-2025-49267P3HIGHCVSS 8.5≤ 3.28.32025-08-14
CVE-2025-49267 [HIGH] CWE-89 CVE-2025-49267: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Blind SQL Injection.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.28.3.
nvd
CVE-2026-66470P3HIGHCVSS 7.1≥ n/a, ≤ 3.29.102026-08-06
CVE-2026-66470 [HIGH] CWE-862 CVE-2026-66470: Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
nvd
CVE-2025-49303P3MEDIUMCVSS 6.8≤ 3.28.72025-07-04
CVE-2025-49303 [MEDIUM] CWE-22 CVE-2025-49303: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Path Traversal.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.28.7.
nvd
CVE-2026-66638P4MEDIUMCVSS 6.5≥ n/a, ≤ 3.29.102026-08-18
CVE-2026-66638 [MEDIUM] CWE-79 CVE-2026-66638: Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.
nvd
CVE-2025-26987P4MEDIUMCVSS 6.1≤ 3.25.172025-02-25
CVE-2025-26987 [MEDIUM] CWE-79 CVE-2025-26987: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shabti Kaplan Frontend Admin by DynamiApps acf-frontend-form-element allows Reflected XSS.This issue affects Frontend Admin by DynamiApps: from n/a through <= 3.25.17.
nvd