HIGH 8.7 NVD
CVE-2026-82657
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can r
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.
References
- https://github.com/Admidio/admidio/security/advisories/GHSA-mg9h-42f8-2pmm
- https://www.vulncheck.com/advisories/admidio-before-5.0.12-authentication-bypass-via-rss-f
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-30 via NVD.
vulnfeed aggregates 11475 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.