icz records
9 published records for vendor icz.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-24913No exploit | SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-89 | High8.7 | — | 0.3% | Apr 8, 2026 |
27Monitor | CVE-2015-5643No exploit | The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitraricz · matchasns · CWE-94 | Medium6.8 | — | 1.3% | Oct 5, 2015 |
27Monitor | CVE-2015-5644No exploit | The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHicz · matchasns · CWE-94 | Medium6.8 | — | 1.3% | Oct 5, 2015 |
27Monitor | CVE-2012-1237No exploit | Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitraryicz · sencha sns · CWE-352 | Medium6.8 | — | 0.6% | Apr 6, 2012 |
26Monitor | CVE-2015-5645No exploit | ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.icz · matchasns · CWE-264 | Medium6.5 | — | 1.3% | Oct 5, 2015 |
26Monitor | CVE-2015-5642No exploit | Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commandsicz · matchasns · CWE-89 | Medium6.5 | — | 1.0% | Oct 5, 2015 |
20Monitor | CVE-2026-33273No exploit | Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.icz · matcha invoice · CWE-434 | Medium5.1 | — | 0.4% | Apr 8, 2026 |
20Monitor | CVE-2026-27787No exploit | Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.icz · matcha sns · CWE-79 | Medium5.1 | — | 0.2% | Apr 8, 2026 |
17Monitor | CVE-2012-1238No exploit | Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.icz · sencha sns | Medium4.3 | — | 1.2% | Apr 6, 2012 |
- CVE-2026-2491334Monitor
SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier.
HighCVSS 8.7No exploitEPSS 0%icz · matcha invoiceApr 8, 2026
- CVE-2015-564327Monitor
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrar
MediumCVSS 6.8No exploitEPSS 1%icz · matchasnsOct 5, 2015
- CVE-2015-564427Monitor
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PH
MediumCVSS 6.8No exploitEPSS 1%icz · matchasnsOct 5, 2015
- CVE-2012-123727Monitor
Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary
MediumCVSS 6.8No exploitEPSS 1%icz · sencha snsApr 6, 2012
- CVE-2015-564526Monitor
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
MediumCVSS 6.5No exploitEPSS 1%icz · matchasnsOct 5, 2015
- CVE-2015-564226Monitor
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands
MediumCVSS 6.5No exploitEPSS 1%icz · matchasnsOct 5, 2015
- CVE-2026-3327320Monitor
Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier.
MediumCVSS 5.1No exploitEPSS 0%icz · matcha invoiceApr 8, 2026
- CVE-2026-2778720Monitor
Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier.
MediumCVSS 5.1No exploitEPSS 0%icz · matcha snsApr 8, 2026
- CVE-2012-123817Monitor
Session fixation vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack web sessions via unspecified vectors.
MediumCVSS 4.3No exploitEPSS 1%icz · sencha snsApr 6, 2012