Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

actualbudget — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting actualbudget. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page documents security vulnerabilities associated with the actualbudget vendor, specifically focusing on weakness classifications relevant to personal finance management software. It aggregates findings across common vulnerability types such as input validation errors, insufficient access control, and potential data exposure issues that may affect users of the platform. The collected data encompasses reported weaknesses from early 2021 through the present, providing a historical perspective on the product's security landscape during a period of significant user adoption and feature expansion. Readers can use this resource to track the vendor’s security advisories over time, understanding how issues are disclosed and resolved. Additionally, the page allows users to deepen their understanding of specific weakness classes by examining real-world examples within the context of the application’s architecture. Users may also look up the product’s vulnerability history to assess trends, frequency, and the nature of past security incidents. This structured overview supports developers, security analysts, and end-users in evaluating the risk profile of the software and making informed decisions regarding updates and mitigation strategies. The content is organized to facilitate easy navigation between different vulnerability types and release versions, ensuring that stakeholders can quickly identify relevant information without sifting through unrelated technical noise or unverified reports.

Found 12 results / 12 Clear Filters
Top products by actualbudget: actual
CVE ID Title CVSS Severity Published
CVE-2026-57449 Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token — actual CWE-200 7.1 High 2026-09-25
CVE-2026-49229 Actual: Disabled OpenID users keep access through existing session tokens — actual CWE-613 8.3 High 2026-07-07
CVE-2026-50179 Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields — actual CWE-1236 4.2 Medium 2026-07-07
CVE-2026-46700 Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets — actual CWE-285 4.3 Medium 2026-07-07
CVE-2026-46672 Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper — actual CWE-1236 4.6 Medium 2026-07-07
CVE-2026-50007 Actual: Shared users can perform owner-only file management actions — actual CWE-862 - - 2026-07-07
CVE-2026-43872 actual-server has a path traversal vulnerability — actual CWE-22 - - 2026-06-12
CVE-2026-42890 actual Allows Electron to Run As Node — actual CWE-94 - - 2026-06-12
CVE-2026-42604 Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config` — actual CWE-863 - - 2026-06-12
CVE-2026-33318 Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers — actual CWE-284 8.8 High 2026-04-24
CVE-2026-27638 ActualBudget missing authorization in sync endpoints allows cross-user budget file access in multi-user mode — actual CWE-862 8.1AI High AI 2026-02-26
CVE-2026-27584 ActualBudget server is Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints — actual CWE-306 7.5 - 2026-02-24

This page lists every published CVE security advisory associated with actualbudget. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.