FrontAccounting
2 known vulnerabilities in FrontAccounting, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-80211 CVSS 8.2 high FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password'])…
- CVE-2026-80210 CVSS 7.1 high FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden…