eladmin records
15 published records for vendor eladmin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-266 Incorrect Privilege Assignment2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-22978No exploit | eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.eladmin · eladmin · CWE-74 | Critical9.8 | — | 0.6% | Feb 3, 2025 |
39Monitor | CVE-2024-44677No exploit | eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the Databeladmin · eladmin · CWE-918 | Critical9.8 | — | 0.5% | Sep 10, 2024 |
28Monitor | CVE-2024-51243No exploit | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of thiseladmin · eladmin · CWE-94 | High7.2 | — | 1.0% | Oct 30, 2024 |
26Monitor | CVE-2024-51242No exploit | A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java.eladmin · eladmin · CWE-918 | Medium6.5 | — | 0.4% | Oct 30, 2024 |
26Monitor | CVE-2025-70997No exploit | A vulnerability has been discovered in eladmin v2.7 and before.eladmin · eladmin · CWE-863 | Medium6.5 | — | 0.2% | Feb 4, 2026 |
25Monitor | CVE-2025-9239No exploit | elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryptioneladmin · eladmin · CWE-310 | Medium6.3 | — | 0.2% | Aug 20, 2025 |
22Monitor | CVE-2025-8530No exploit | elunez eladmin Druid application-prod.yml default credentialseladmin · eladmin · CWE-1392 | Medium5.5 | — | 0.5% | Aug 4, 2025 |
21Monitor | CVE-2025-3250No exploit | elunez eladmin Maintenance Management Module testConnect deserializationeladmin · eladmin · CWE-20 | Medium5.3 | — | 0.5% | Apr 4, 2025 |
20Monitor | CVE-2024-7458No exploit | elunez eladmin Database Management/Deployment Management upload path traversaleladmin · eladmin · CWE-27 | Medium5.1 | — | 0.8% | Aug 4, 2024 |
20Monitor | CVE-2025-2855No exploit | elunez eladmin upload checkFile deserializationeladmin · eladmin · CWE-20 | Medium5.1 | — | 0.5% | Mar 27, 2025 |
19Monitor | CVE-2024-44676No exploit | eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreControleladmin · eladmin · CWE-79 | Medium4.8 | — | 0.5% | Sep 10, 2024 |
8Monitor | CVE-2025-9240No exploit | elunez eladmin info information disclosureeladmin · eladmin · CWE-200 | Low2.1 | — | 0.3% | Aug 20, 2025 |
8Monitor | CVE-2025-9241No exploit | elunez eladmin exportUser csv injectioneladmin · eladmin · CWE-74 | Low2.1 | — | 0.3% | Aug 20, 2025 |
8Monitor | CVE-2025-10084No exploit | elunez eladmin SysLogController 1 queryErrorLogDetail improper authorizationeladmin · eladmin · CWE-266 | Low2.1 | — | 0.3% | Sep 8, 2025 |
5Monitor | CVE-2025-10014No exploit | elunez eladmin Email Address updateEmail updateUserEmail improper authorizationeladmin · eladmin · CWE-266 | Low1.3 | — | 0.3% | Sep 5, 2025 |
- CVE-2025-2297839Monitor
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
CriticalCVSS 9.8No exploitEPSS 1%eladmin · eladminFeb 3, 2025
- CVE-2024-4467739Monitor
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the Datab
CriticalCVSS 9.8No exploitEPSS 0%eladmin · eladminSep 10, 2024
- CVE-2024-5124328Monitor
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this
HighCVSS 7.2No exploitEPSS 1%eladmin · eladminOct 30, 2024
- CVE-2024-5124226Monitor
A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java.
MediumCVSS 6.5No exploitEPSS 0%eladmin · eladminOct 30, 2024
- CVE-2025-7099726Monitor
A vulnerability has been discovered in eladmin v2.7 and before.
MediumCVSS 6.5No exploitEPSS 0%eladmin · eladminFeb 4, 2026
- CVE-2025-923925Monitor
elunez eladmin DES Key EncryptUtils.java EncryptUtils inadequate encryption
MediumCVSS 6.3No exploitEPSS 0%eladmin · eladminAug 20, 2025
- CVE-2025-853022Monitor
elunez eladmin Druid application-prod.yml default credentials
MediumCVSS 5.5No exploitEPSS 0%eladmin · eladminAug 4, 2025
- CVE-2025-325021Monitor
elunez eladmin Maintenance Management Module testConnect deserialization
MediumCVSS 5.3No exploitEPSS 0%eladmin · eladminApr 4, 2025
- CVE-2024-745820Monitor
elunez eladmin Database Management/Deployment Management upload path traversal
MediumCVSS 5.1No exploitEPSS 1%eladmin · eladminAug 4, 2024
- CVE-2025-285520Monitor
elunez eladmin upload checkFile deserialization
MediumCVSS 5.1No exploitEPSS 1%eladmin · eladminMar 27, 2025
- CVE-2024-4467619Monitor
eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code via LocalStoreControl
MediumCVSS 4.8No exploitEPSS 1%eladmin · eladminSep 10, 2024
- CVE-2025-92408Monitor
elunez eladmin info information disclosure
LowCVSS 2.1No exploitEPSS 0%eladmin · eladminAug 20, 2025
- CVE-2025-92418Monitor
elunez eladmin exportUser csv injection
LowCVSS 2.1No exploitEPSS 0%eladmin · eladminAug 20, 2025
- CVE-2025-100848Monitor
elunez eladmin SysLogController 1 queryErrorLogDetail improper authorization
LowCVSS 2.1No exploitEPSS 0%eladmin · eladminSep 8, 2025
- CVE-2025-100145Monitor
elunez eladmin Email Address updateEmail updateUserEmail improper authorization
LowCVSS 1.3No exploitEPSS 0%eladmin · eladminSep 5, 2025