Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

actualbudget — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting actualbudget. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities, weaknesses, and associated tags for the vendor actualbudget, specifically focusing on its open-source budgeting software. It collects data on security flaws, misconfigurations, and implementation errors affecting the Actual Budget application across various releases. The content covers vulnerability records from the earliest available reports up to the present day, ensuring a comprehensive historical view of the product's security landscape. Readers can use this resource to track a vendor's advisories and stay informed about newly disclosed issues. It also allows users to understand a specific weakness class by examining how it manifests in this particular software ecosystem. Additionally, visitors can look up a product's vulnerability history to assess long-term security trends and remediation efforts. This aggregation supports developers, security analysts, and end-users in evaluating the risk posture of actualbudget. By consolidating diverse sources, the page provides a unified view of known defects, helping stakeholders prioritize patching and mitigation strategies. The data is organized to facilitate easy navigation through different severity levels and attack vectors, enabling informed decision-making regarding software updates and security controls. This resource serves as a neutral, factual reference point for understanding the technical and operational security implications associated with using or maintaining the actualbudget platform.

Top products by actualbudget: actual
CVE IDTitleCVSSSeverityPublished
CVE-2026-49229 Actual: Disabled OpenID users keep access through existing session tokens — actualCWE-613 8.3 High2026-07-07
CVE-2026-50179 Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields — actualCWE-1236 4.2 Medium2026-07-07
CVE-2026-46700 Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets — actualCWE-285 4.3 Medium2026-07-07
CVE-2026-46672 Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper — actualCWE-1236 4.6 Medium2026-07-07
CVE-2026-50007 Actual: Shared users can perform owner-only file management actions — actualCWE-862--2026-07-07
CVE-2026-43872 actual-server has a path traversal vulnerability — actualCWE-22--2026-06-12
CVE-2026-42890 actual Allows Electron to Run As Node — actualCWE-94--2026-06-12
CVE-2026-42604 Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config` — actualCWE-863--2026-06-12
CVE-2026-33318 Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers — actualCWE-284 8.8 High2026-04-24
CVE-2026-27638 ActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-user mode — actualCWE-862 8.1AIHighAI2026-02-26
CVE-2026-27584 ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints — actualCWE-306 7.5 -2026-02-24

This page lists every published CVE security advisory associated with actualbudget. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.