Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Fineract — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Apache Fineract, with AI-generated Chinese analysis, references, and POCs.

Apache Fineract, a product of the Apache Software Foundation, is cataloged here for its associated Common Weakness Enumeration (CWE) security vulnerabilities. This page aggregates reported security issues affecting the Apache Fineract core banking platform, covering data spanning from the initial public releases through the most recent patch updates. By providing a centralized view of these security events, the resource enables security professionals to efficiently track vendor security advisories as they are issued by the Apache community. Users can also gain a deeper understanding of specific weakness classes that have impacted this financial infrastructure software, analyzing patterns in coding errors or architectural flaws. Furthermore, the comprehensive history allows stakeholders to look up a product's vulnerability timeline, helping organizations assess their risk exposure and prioritize remediation efforts based on historical data. This structured approach ensures that developers, auditors, and risk managers have accurate, consolidated information regarding the security posture of Apache Fineract over time. The collection focuses on verified reports and official announcements to maintain high integrity and relevance for enterprise security operations.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-57821 Apache Fineract: Office list: SQL Injection via Subquery in orderBy CWE-89--2026-07-15
CVE-2026-35152 Apache Fineract: SQL injection in runreports endpoint CWE-89--2026-07-15
CVE-2026-56287 Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure CWE-89--2026-07-15
CVE-2025-58137 Apache Fineract: IDOR via self-service API CWE-639 7.5AIHighAI2025-12-12
CVE-2025-58130 Apache Fineract: Server Key not masked CWE-522 9.1AICriticalAI2025-12-12
CVE-2025-23408 Apache Fineract: weak password policy CWE-521 9.8AICriticalAI2025-12-12
CVE-2024-32838 Apache Fineract: SQL injection vulnerabilities in offices API endpoint CWE-89 8.8 -2025-02-12
CVE-2024-23537 Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific permissions, to escalate their privileges to any role. CWE-269 8.4 High2024-03-29
CVE-2024-23538 Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. CWE-89 9.9 Critical2024-03-29
CVE-2024-23539 Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoints was vulnerable to SQL injection attacks, potentially allowing attackers to manipulate database queries. CWE-89 8.3 High2024-03-29
CVE-2023-25197 apache fineract: SQL injection vulnerability in certain procedure calls CWE-89 9.8 -2023-03-28
CVE-2023-25196 Apache Fineract: SQL injection vulnerability CWE-89 8.1 -2023-03-28
CVE-2023-25195 Apache Fineract: SSRF template type vulnerability in certain authenticated users CWE-918 8.1 -2023-03-28
CVE-2022-44635 Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal CWE-22 8.8 -2022-11-29
CVE-2020-17514 disabled hostname verificiation 7.4 -2021-05-27
CVE-2018-20243 fineract jira 安全漏洞 7.5 -2020-10-13
CVE-2018-11801 Apache Fineract SQL注入漏洞 9.8 -2019-06-11
CVE-2018-11800 Apache Fineract SQL注入漏洞 9.8 -2019-06-11
CVE-2018-1292 Apache Fineract 安全漏洞 8.1 -2018-04-20
CVE-2018-1291 Apache Fineract 安全漏洞 8.1 -2018-04-20
CVE-2018-1290 Apache Fineract SQL注入漏洞 9.8 -2018-04-20
CVE-2018-1289 Apache Fineract 安全漏洞 8.8 -2018-04-20
CVE-2017-5663 Apache Fineract 安全漏洞 8.8 -2017-12-14

All 23 known CVE vulnerabilities affecting Apache Fineract with full Chinese analysis, references, and POCs where available.