machform records
15 published records for vendor machform.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2018-6411Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-434 | Critical9.8 | — | 5.6% | May 26, 2018 |
40Plan | CVE-2018-6410Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-89 | Critical9.8 | — | 4.7% | May 26, 2018 |
39Monitor | CVE-2024-37762Proof of concept | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.machform · machform · CWE-434 | Critical9.9 | — | 1.5% | Jul 1, 2024 |
35Monitor | CVE-2024-37765Proof of concept | Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.machform · machform · CWE-89 | High8.8 | — | 0.8% | Jul 1, 2024 |
35Monitor | CVE-2021-20102No exploit | Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.machform · machform · CWE-352 | High8.8 | — | 0.5% | Jun 29, 2021 |
33Monitor | CVE-2021-20104No exploit | Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uplmachform · machform · CWE-434 | High8.1 | — | 2.2% | Jun 29, 2021 |
31Monitor | CVE-2013-4948Proof of concept | SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.machform · machform · CWE-89 | High7.5 | — | 3.5% | Jul 29, 2013 |
29Monitor | CVE-2013-4949Proof of concept | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fimachform · machform | Medium6.8 | — | 5.5% | Jul 29, 2013 |
25Monitor | CVE-2018-6409Proof of concept | An issue was discovered in Appnitro MachForm before 4.2.3.machform · machform · CWE-22 | Medium5.3 | — | 14.1% | May 26, 2018 |
24Monitor | CVE-2021-20105No exploit | Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.machform · machform · CWE-601 | Medium6.1 | — | 0.7% | Jun 29, 2021 |
24Monitor | CVE-2021-20101No exploit | Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.machform · machform · CWE-74 | Medium6.1 | — | 0.7% | Jun 29, 2021 |
24Monitor | CVE-2021-20103No exploit | Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded withmachform · machform · CWE-79 | Medium6.1 | — | 0.7% | Jun 29, 2021 |
21Monitor | CVE-2024-37763Proof of concept | MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can viemachform · machform · CWE-79 | Medium5.4 | — | 0.7% | Jul 1, 2024 |
21Monitor | CVE-2024-37764Proof of concept | MachForm up to version 19 is affected by an authenticated stored cross-site scripting.machform · machform · CWE-79 | Medium5.4 | — | 0.6% | Jul 1, 2024 |
18Monitor | CVE-2013-4950Proof of concept | Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the elmachform · machform · CWE-79 | Medium4.3 | — | 3.9% | Jul 29, 2013 |
- CVE-2018-641141Plan
An issue was discovered in Appnitro MachForm before 4.2.3.
CriticalCVSS 9.8Proof of conceptEPSS 6%machform · machformMay 26, 2018
- CVE-2018-641040Plan
An issue was discovered in Appnitro MachForm before 4.2.3.
CriticalCVSS 9.8Proof of conceptEPSS 5%machform · machformMay 26, 2018
- CVE-2024-3776239Monitor
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
CriticalCVSS 9.9Proof of conceptEPSS 1%machform · machformJul 1, 2024
- CVE-2024-3776535Monitor
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
HighCVSS 8.8Proof of conceptEPSS 1%machform · machformJul 1, 2024
- CVE-2021-2010235Monitor
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
HighCVSS 8.8No exploitEPSS 1%machform · machformJun 29, 2021
- CVE-2021-2010433Monitor
Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments upl
HighCVSS 8.1No exploitEPSS 2%machform · machformJun 29, 2021
- CVE-2013-494831Monitor
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.
HighCVSS 7.5Proof of conceptEPSS 3%machform · machformJul 29, 2013
- CVE-2013-494929Monitor
Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fi
MediumCVSS 6.8Proof of conceptEPSS 5%machform · machformJul 29, 2013
- CVE-2018-640925Monitor
An issue was discovered in Appnitro MachForm before 4.2.3.
MediumCVSS 5.3Proof of conceptEPSS 14%machform · machformMay 26, 2018
- CVE-2021-2010524Monitor
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
MediumCVSS 6.1No exploitEPSS 1%machform · machformJun 29, 2021
- CVE-2021-2010124Monitor
Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.
MediumCVSS 6.1No exploitEPSS 1%machform · machformJun 29, 2021
- CVE-2021-2010324Monitor
Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with
MediumCVSS 6.1No exploitEPSS 1%machform · machformJun 29, 2021
- CVE-2024-3776321Monitor
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can vie
MediumCVSS 5.4Proof of conceptEPSS 1%machform · machformJul 1, 2024
- CVE-2024-3776421Monitor
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
MediumCVSS 5.4Proof of conceptEPSS 1%machform · machformJul 1, 2024
- CVE-2013-495018Monitor
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the el
MediumCVSS 4.3Proof of conceptEPSS 4%machform · machformJul 29, 2013