{"api_version":"v1","generated_at":"2026-10-07T15:50:00+00:00","product":{"cve_count":19,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-fineract-c99bd4c3d7b8","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"apache fineract","next_cursor":null,"observations":[{"affected":"\u2264 1.14.0","affected_versions_present":true,"cve_id":"CVE-2026-57821","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-57821","fixed":"1.15.0","last_modified":"2026-07-15T12:26:10.244Z","patch_url":"https://github.com/apache/fineract/pull/6048","primary_source":"","published":"2026-07-15T09:20:09.239Z"},{"affected":"\u2264 1.14.0","affected_versions_present":true,"cve_id":"CVE-2026-35152","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35152","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-06T11:21:12.960Z","patch_url":"https://github.com/apache/fineract/pull/5980","primary_source":"","published":"2026-07-15T09:19:54.983Z"},{"affected":"\u2264 1.14.0","affected_versions_present":true,"cve_id":"CVE-2026-56287","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56287","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-15T14:32:08.722Z","patch_url":"https://github.com/apache/fineract/pull/6020","primary_source":"","published":"2026-07-15T09:19:38.262Z"},{"affected":"\u2264 1.11.0","affected_versions_present":true,"cve_id":"CVE-2025-58137","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58137","fixed":"1.12.1","last_modified":"2025-12-12T19:35:44.785Z","patch_url":"https://lists.apache.org/thread/gz3zhoghlclch3rdnzyrdcf69c0507ww","primary_source":"","published":"2025-12-12T09:21:00.374Z"},{"affected":"\u2264 1.11.0","affected_versions_present":true,"cve_id":"CVE-2025-58130","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58130","fixed":"1.12.1","last_modified":"2025-12-12T19:38:02.717Z","patch_url":"https://lists.apache.org/thread/d9zpkc86zk265523tfvbr8w7gyr6onoy","primary_source":"","published":"2025-12-12T09:20:06.930Z"},{"affected":"\u2264 1.10.1","affected_versions_present":true,"cve_id":"CVE-2025-23408","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-23408","fixed":"1.11.0","last_modified":"2025-12-18T15:34:00.875Z","patch_url":"https://lists.apache.org/thread/bdlb6wl968yh1n48mr5npsk2spo6dncf","primary_source":"","published":"2025-12-12T09:18:59.147Z"},{"affected":"1.4 \u2264 1.9","affected_versions_present":true,"cve_id":"CVE-2024-32838","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32838","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-12T18:03:27.737Z","patch_url":"","primary_source":"","published":"2025-02-12T09:44:15.943Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2024-23537","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23537","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:39:45.238Z","patch_url":"","primary_source":"","published":"2024-03-29T14:38:05.738Z"},{"affected":"< 1.8.5","affected_versions_present":true,"cve_id":"CVE-2024-23538","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23538","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:39:45.863Z","patch_url":"","primary_source":"","published":"2024-03-29T14:37:40.374Z"},{"affected":"\u2264 1.8.4","affected_versions_present":true,"cve_id":"CVE-2024-23539","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-23539","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:39:46.405Z","patch_url":"","primary_source":"","published":"2024-03-29T14:36:57.919Z"},{"affected":"1.4 \u2264 1.8.2","affected_versions_present":true,"cve_id":"CVE-2023-25197","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-25197","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-23T15:14:18.730Z","patch_url":"","primary_source":"","published":"2023-03-28T11:17:19.026Z"},{"affected":"1.4 \u2264 1.8.2","affected_versions_present":true,"cve_id":"CVE-2023-25196","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-25196","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-23T15:14:44.993Z","patch_url":"","primary_source":"","published":"2023-03-28T11:16:57.603Z"},{"affected":"1.4 \u2264 1.8.3","affected_versions_present":true,"cve_id":"CVE-2023-25195","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-25195","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-23T15:16:08.717Z","patch_url":"","primary_source":"","published":"2023-03-28T11:16:28.304Z"},{"affected":"Apache Fineract 1.8 \u2264 1.8.0; Apache Fineract 1.7 \u2264 1.7.0","affected_versions_present":true,"cve_id":"CVE-2022-44635","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-44635","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-25T14:51:14.718Z","patch_url":"","primary_source":"","published":"2022-11-29T00:00:00.000Z"},{"affected":"Apache Fineract < 1.5.0","affected_versions_present":true,"cve_id":"CVE-2020-17514","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-17514","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T14:00:48.549Z","patch_url":"https://issues.apache.org/jira/browse/FINERACT-1211","primary_source":"","published":"2021-05-27T12:10:10.000Z"},{"affected":"1.0.0; 0.6.0-incubating; 0.5.0-incubating; 0.4.0-incubating","affected_versions_present":true,"cve_id":"CVE-2018-1292","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1292","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T19:56:06.458Z","patch_url":"","primary_source":"","published":"2018-04-20T18:00:00.000Z"},{"affected":"1.0.0; 0.6.0-incubating; 0.5.0-incubating; 0.4.0-incubating","affected_versions_present":true,"cve_id":"CVE-2018-1291","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1291","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T19:20:16.288Z","patch_url":"","primary_source":"","published":"2018-04-20T18:00:00.000Z"},{"affected":"1.0.0; 0.6.0-incubating; 0.5.0-incubating; 0.4.0-incubating","affected_versions_present":true,"cve_id":"CVE-2018-1290","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1290","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-16T22:03:02.684Z","patch_url":"","primary_source":"","published":"2018-04-20T18:00:00.000Z"},{"affected":"1.0.0; 0.6.0-incubating; 0.5.0-incubating; 0.4.0-incubating","affected_versions_present":true,"cve_id":"CVE-2018-1289","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1289","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T04:08:48.966Z","patch_url":"","primary_source":"","published":"2018-04-20T18:00:00.000Z"},{"affected":"0.4.0-incubating; 0.5.0-incubating; 0.6.0-incubating","affected_versions_present":true,"cve_id":"CVE-2017-5663","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-5663","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T01:05:44.339Z","patch_url":"","primary_source":"","published":"2017-12-14T15:00:00.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Apache Software Foundation"}}
