ProcessMaker records
6 published records for vendor processmaker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-281 Improper Preservation of Permissions1
- CWE-502 Deserialization of Untrusted Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2016-9045No exploit | A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community.processmaker · processmaker · CWE-502 | High8.8 | — | 2.2% | Sep 17, 2018 |
36Monitor | CVE-2022-38577Proof of concept | ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page.processmaker · processmaker · CWE-281 | High8.8 | — | 2.2% | Sep 19, 2022 |
36Monitor | CVE-2020-13525No exploit | The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMprocessmaker · processmaker · CWE-89 | High8.8 | — | 1.7% | Dec 3, 2020 |
36Monitor | CVE-2020-13526No exploit | SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11.processmaker · processmaker · CWE-89 | High8.8 | — | 1.7% | Dec 10, 2020 |
29Monitor | CVE-2016-9048No exploit | Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community.processmaker · processmaker · CWE-89 | High7.4 | — | 0.8% | Sep 10, 2018 |
26Monitor | CVE-2024-25506No exploit | Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control CWE-79 | Medium6.5 | — | 0.3% | Mar 28, 2024 |
- CVE-2016-904536Monitor
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community.
HighCVSS 8.8No exploitEPSS 2%processmaker · processmakerSep 17, 2018
- CVE-2022-3857736Monitor
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page.
HighCVSS 8.8Proof of conceptEPSS 2%processmaker · processmakerSep 19, 2022
- CVE-2020-1352536Monitor
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessM
HighCVSS 8.8No exploitEPSS 2%processmaker · processmakerDec 3, 2020
- CVE-2020-1352636Monitor
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11.
HighCVSS 8.8No exploitEPSS 2%processmaker · processmakerDec 10, 2020
- CVE-2016-904829Monitor
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community.
HighCVSS 7.4No exploitEPSS 1%processmaker · processmakerSep 10, 2018
- CVE-2024-2550626Monitor
Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control
MediumCVSS 6.5No exploitEPSS 0%Mar 28, 2024