Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-82655: Admidio before 5.0.12 can let outsiders read passwords
CVE-2026-82655 · published 4 days ago
Summary
If you are using Admidio version older than 5.0.12, someone on the internet could trick the software into revealing the contents of your database, including user passwords. This can happen without needing a valid login. Upgrade to the latest Admidio release as soon as possible and verify that only trusted users have access to the system.
What to do
- Update admidio admidio to version 5.0.12 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| admidio | admidio | < 5.0.12 |
Original advisory text
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Atta...
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject SQL through relation_type_list to extract database contents including password hashes and user credentials.
References
Severity
8.7
High
CVSS 3.1: 7.5 (MITRE)
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta