Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-37762 | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. NVD description · AI analysis pending | 9.9 group max | 1% | PoC |
| — | |
| CVE-2021-20102 | Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place. Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2018-6411 | An issue was discovered in Appnitro MachForm before 4.2.3. An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection. NVD description · AI analysis pending | 9.8 group max | 6% | PoC ×2 |
| — |