Skip to content
Noroxi

machform records

15 published records for vendor machform.

All records

15 records
  • An issue was discovered in Appnitro MachForm before 4.2.3.

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    machform · machformMay 26, 2018

  • An issue was discovered in Appnitro MachForm before 4.2.3.

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    machform · machformMay 26, 2018

  • MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

    CriticalCVSS 9.9Proof of conceptEPSS 1%

    machform · machformJul 1, 2024

  • Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

    HighCVSS 8.8Proof of conceptEPSS 1%

    machform · machformJul 1, 2024

  • Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.

    HighCVSS 8.8No exploitEPSS 1%

    machform · machformJun 29, 2021

  • Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments upl

    HighCVSS 8.1No exploitEPSS 2%

    machform · machformJun 29, 2021

  • CVE-2013-4948
    31Monitor

    SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.

    HighCVSS 7.5Proof of conceptEPSS 3%

    machform · machformJul 29, 2013

  • CVE-2013-4949
    29Monitor

    Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP fi

    MediumCVSS 6.8Proof of conceptEPSS 5%

    machform · machformJul 29, 2013

  • CVE-2018-6409
    25Monitor

    An issue was discovered in Appnitro MachForm before 4.2.3.

    MediumCVSS 5.3Proof of conceptEPSS 14%

    machform · machformMay 26, 2018

  • Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    machform · machformJun 29, 2021

  • Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers.

    MediumCVSS 6.1No exploitEPSS 1%

    machform · machformJun 29, 2021

  • Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attachments uploaded with

    MediumCVSS 6.1No exploitEPSS 1%

    machform · machformJun 29, 2021

  • MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can vie

    MediumCVSS 5.4Proof of conceptEPSS 1%

    machform · machformJul 1, 2024

  • MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

    MediumCVSS 5.4Proof of conceptEPSS 1%

    machform · machformJul 1, 2024

  • CVE-2013-4950
    18Monitor

    Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the el

    MediumCVSS 4.3Proof of conceptEPSS 4%

    machform · machformJul 29, 2013