cjbi admin3
4 known vulnerabilities in cjbi admin3, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-92921 CVSS 6.9 medium admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function…
- CVE-2026-92920 CVSS 5.3 medium admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated…
- CVE-2026-92919 CVSS 7.2 high admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files…
- CVE-2026-92918 CVSS 8.7 high admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with…