Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Frontend Admin by DynamiApps — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Frontend Admin by DynamiApps, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with the Frontend Admin product developed by DynamiApps, focusing on common vulnerability classifications. It aggregates disclosed security issues affecting this specific frontend administration tool, covering vulnerabilities reported over the past several years up to the current date. By centralizing this data, the resource provides a comprehensive view of the security landscape for DynamiApps’ software, allowing security professionals and administrators to stay informed about known risks. Readers can use this page to track the vendor’s history of security advisories, gaining insight into their response patterns and disclosure timelines. Additionally, users can explore specific weakness classes to understand the nature of flaws found in the product, such as injection risks, cross-site scripting, or authorization bypasses. The aggregated information serves as a historical record of the product’s vulnerability status, helping teams assess risk levels and prioritize patching efforts. This collection does not include specific CVE identifiers to maintain focus on the broader trends and categories of security defects rather than individual incident tracking. It aims to facilitate a deeper understanding of how frontend administrative interfaces are typically compromised and what mitigation strategies have been employed over time. Whether you are conducting a vendor risk assessment or performing a technical review of the Frontend Admin application, this page offers a structured overview of the security challenges faced by the product. It supports informed decision-making regarding software procurement and maintenance without relying on fragmented or outdated sources.

Vendor: Shabti Kaplan

CVE IDTitleCVSSSeverityPublished
CVE-2026-10039 Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter CWE-89 4.9 Medium2026-05-29
CVE-2026-6226 Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection CWE-269 8.8 High2026-05-28
CVE-2026-7802 Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter CWE-862 8.8 High2026-05-28
CVE-2026-6228 Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form CWE-269 8.8 High2026-05-15
CVE-2026-3328 Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts CWE-502 7.2 High2026-03-26
CVE-2025-14741 Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element CWE-862 9.1 Critical2026-01-09
CVE-2025-14937 Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field' CWE-79 7.2 High2026-01-09
CVE-2025-14736 Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field CWE-269 9.8 Critical2026-01-09
CVE-2025-13342 Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update CWE-862 9.8 Critical2025-12-03
CVE-2025-49267 WordPress Frontend Admin by DynamiApps plugin <= 3.28.3 - SQL Injection vulnerability CWE-89 8.5 High2025-08-14
CVE-2025-49303 WordPress Frontend Admin by DynamiApps plugin <= 3.28.7 - Arbitrary File Download Vulnerability CWE-22 6.8 Medium2025-07-04
CVE-2025-26987 WordPress Frontend Admin by DynamiApps plugin <= 3.25.17 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2025-02-25
CVE-2024-11722 Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection CWE-89 5.9 Medium2024-12-21
CVE-2024-11721 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation CWE-269 8.1 High2024-12-14
CVE-2024-11720 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2024-12-14
CVE-2024-3729 Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation CWE-636 9.8 Critical2024-05-02
CVE-2023-51411 WordPress Frontend Admin by DynamiApps Plugin <= 3.18.3 is vulnerable to Arbitrary File Upload CWE-434 10.0 Critical2023-12-29

All 17 known CVE vulnerabilities affecting Frontend Admin by DynamiApps with full Chinese analysis, references, and POCs where available.