appRain records
38 published records for vendor apprain.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.6%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')29
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
38 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2012-1153Weaponized | Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to executeapprain · apprain | Medium6.8 | — | 32.4% | Oct 6, 2012 |
34Monitor | CVE-2024-58279No exploit | appRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Uploadapprain · apprain · CWE-434 | High8.6 | — | 1.0% | Dec 10, 2025 |
34Monitor | CVE-2025-41034No exploit | SQL injection vulnerability in appRain CMFapprain · apprain · CWE-89 | High8.7 | — | 0.4% | Sep 4, 2025 |
34Monitor | CVE-2025-41033No exploit | SQL injection vulnerability in appRain CMFapprain · apprain · CWE-89 | High8.7 | — | 0.4% | Sep 4, 2025 |
34Monitor | CVE-2025-41032No exploit | SQL injection vulnerability in appRain CMFapprain · apprain · CWE-89 | High8.7 | — | 0.4% | Sep 4, 2025 |
31Monitor | CVE-2013-6058Proof of concept | SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to apprain · apprain · CWE-89 | High7.5 | — | 2.5% | Nov 14, 2013 |
31Monitor | CVE-2011-5229Proof of concept | SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbiapprain · apprain · CWE-89 | High7.5 | — | 2.2% | Oct 25, 2012 |
28Monitor | CVE-2025-41035No exploit | Path Traversal vulnerability in appRain CMFapprain · apprain · CWE-22 | High7.1 | — | 0.7% | Sep 4, 2025 |
20Monitor | CVE-2011-3704No exploit | appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation paapprain · apprain · CWE-200 | Medium5.0 | — | 1.3% | Sep 23, 2011 |
20Monitor | CVE-2025-41037No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41036No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41038No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41045No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41039No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41040No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41041No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41042No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41043No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41044No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41059No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41060No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41061No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41046No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41047No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
20Monitor | CVE-2025-41048No exploit | Stored Cross-Site Scripting vulnerability in appRain CMFapprain · apprain · CWE-79 | Medium5.1 | — | 0.2% | Sep 4, 2025 |
- CVE-2012-115337Monitor
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute
MediumCVSS 6.8WeaponizedEPSS 32%apprain · apprainOct 6, 2012
- CVE-2024-5827934Monitor
appRain CMF 4.0.5 Authenticated Remote Code Execution via Filemanager Upload
HighCVSS 8.6No exploitEPSS 1%apprain · apprainDec 10, 2025
- CVE-2025-4103434Monitor
SQL injection vulnerability in appRain CMF
HighCVSS 8.7No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4103334Monitor
SQL injection vulnerability in appRain CMF
HighCVSS 8.7No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4103234Monitor
SQL injection vulnerability in appRain CMF
HighCVSS 8.7No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2013-605831Monitor
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to
HighCVSS 7.5Proof of conceptEPSS 2%apprain · apprainNov 14, 2013
- CVE-2011-522931Monitor
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbi
HighCVSS 7.5Proof of conceptEPSS 2%apprain · apprainOct 25, 2012
- CVE-2025-4103528Monitor
Path Traversal vulnerability in appRain CMF
HighCVSS 7.1No exploitEPSS 1%apprain · apprainSep 4, 2025
- CVE-2011-370420Monitor
appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pa
MediumCVSS 5.0No exploitEPSS 1%apprain · apprainSep 23, 2011
- CVE-2025-4103720Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4103620Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4103820Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104520Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4103920Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104020Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104120Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104220Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104320Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104420Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4105920Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4106020Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4106120Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104620Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104720Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025
- CVE-2025-4104820Monitor
Stored Cross-Site Scripting vulnerability in appRain CMF
MediumCVSS 5.1No exploitEPSS 0%apprain · apprainSep 4, 2025