Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Fineract — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Apache Fineract, with AI-generated Chinese analysis, references, and POCs.

Apache Fineract is an open-source banking platform developed by The Apache Software Foundation that contains recorded security weaknesses of the Common Weakness Enumeration type. This page aggregates vulnerability data for this specific software component, compiling reported issues from the past ten years to provide a comprehensive historical perspective on its security posture. Visitors can use this resource to track vendor advisories issued by The Apache Software Foundation, understand the characteristics and impact of specific weakness classes affecting the platform, and look up the complete vulnerability history for Apache Fineract to assess long-term risk trends. By centralizing this information, the page serves as a reference point for security researchers, developers, and compliance officers who need to evaluate the integrity of the financial software. The data includes details on severity ratings, affected versions, and remediation status where available, allowing stakeholders to make informed decisions about patching and mitigation strategies. This aggregation helps identify recurring patterns in security flaws, such as injection vulnerabilities or improper access control issues, which are common in complex banking applications. Users can navigate through the entries to see how the development team has addressed past weaknesses and whether similar issues remain unpatched in current releases. This structured view supports proactive security management by highlighting areas that may require additional scrutiny or third-party audit. The goal is to provide transparent, actionable intelligence without overwhelming the reader with unnecessary noise.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2025-58137 Apache Fineract: IDOR via self-service API CWE-639 7.5AIHighAI2025-12-12
CVE-2025-58130 Apache Fineract: Server Key not masked CWE-522 9.1AICriticalAI2025-12-12
CVE-2025-23408 Apache Fineract: weak password policy CWE-521 9.8AICriticalAI2025-12-12
CVE-2024-32838 Apache Fineract: SQL injection vulnerabilities in offices API endpoint CWE-89 8.8 -2025-02-12
CVE-2024-23537 Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. CWE-269 8.4 High2024-03-29
CVE-2024-23538 Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. CWE-89 9.9 Critical2024-03-29
CVE-2024-23539 Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. CWE-89 8.3 High2024-03-29
CVE-2023-25197 apache fineract: SQL injection vulnerability in certain procedure calls CWE-89 9.8 -2023-03-28
CVE-2023-25196 Apache Fineract: SQL injection vulnerability CWE-89 8.1 -2023-03-28
CVE-2023-25195 Apache Fineract: SSRF template type vulnerability in certain authenticated users CWE-918 8.1 -2023-03-28
CVE-2022-44635 Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal CWE-22 8.8 -2022-11-29
CVE-2020-17514 disabled hostname verificiation 7.4 -2021-05-27
CVE-2018-20243 fineract jira 安全漏洞 7.5 -2020-10-13
CVE-2018-11801 Apache Fineract SQL注入漏洞 9.8 -2019-06-11
CVE-2018-11800 Apache Fineract SQL注入漏洞 9.8 -2019-06-11
CVE-2018-1292 Apache Fineract 安全漏洞 8.1 -2018-04-20
CVE-2018-1291 Apache Fineract 安全漏洞 8.1 -2018-04-20
CVE-2018-1290 Apache Fineract SQL注入漏洞 9.8 -2018-04-20
CVE-2018-1289 Apache Fineract 安全漏洞 8.8 -2018-04-20
CVE-2017-5663 Apache Fineract 安全漏洞 8.8 -2017-12-14

All 20 known CVE vulnerabilities affecting Apache Fineract with full Chinese analysis, references, and POCs where available.