Skip to content
Noroxi

ProcessMaker records

6 published records for vendor processmaker.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • CVE-2016-9045
    36Monitor

    A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community.

    HighCVSS 8.8No exploitEPSS 2%

    processmaker · processmakerSep 17, 2018

  • ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page.

    HighCVSS 8.8Proof of conceptEPSS 2%

    processmaker · processmakerSep 19, 2022

  • The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessM

    HighCVSS 8.8No exploitEPSS 2%

    processmaker · processmakerDec 3, 2020

  • SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11.

    HighCVSS 8.8No exploitEPSS 2%

    processmaker · processmakerDec 10, 2020

  • CVE-2016-9048
    29Monitor

    Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community.

    HighCVSS 7.4No exploitEPSS 1%

    processmaker · processmakerSep 10, 2018

  • Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control

    MediumCVSS 6.5No exploitEPSS 0%

    Mar 28, 2024