FrontAccounting

2 known vulnerabilities in FrontAccounting, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-80211 CVSS 8.2 high FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_POST['password'])…
  • CVE-2026-80210 CVSS 7.1 high FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the _token hidden…