CVE-2026-27787
- EPSS 0.03%
- Veröffentlicht 08.04.2026 05:11:11
- Zuletzt bearbeitet 17.04.2026 20:43:36
Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.
CVE-2015-5645
- EPSS 0.44%
- Veröffentlicht 06.10.2015 01:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
CVE-2015-5644
- EPSS 0.6%
- Veröffentlicht 06.10.2015 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
CVE-2015-5643
- EPSS 0.6%
- Veröffentlicht 06.10.2015 01:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
CVE-2015-5642
- EPSS 0.35%
- Veröffentlicht 06.10.2015 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.