Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.5
CVE-2026-78838
- EPSS 0.37%
- Veröffentlicht 08.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 20:20:42
A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted payload into the filter...
7.5
CVE-2026-78837
- EPSS 0.31%
- Veröffentlicht 08.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 19:17:47
A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.
8.1
CVE-2026-78839
- EPSS 0.26%
- Veröffentlicht 04.09.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 20:20:42
An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file.
1