CVE-2025-34097
- EPSS 32.11%
- Veröffentlicht 10.07.2025 19:12:37
- Zuletzt bearbeitet 15.04.2026 00:35:42
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload a malicious .tar plugin file containing arbitrary PHP...
CVE-2024-25506
- EPSS 0.58%
- Veröffentlicht 28.03.2024 20:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.
CVE-2022-38577
- EPSS 14.04%
- Veröffentlicht 19.09.2022 16:15:11
- Zuletzt bearbeitet 03.06.2025 19:15:31
ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.
CVE-2020-13526
- EPSS 1.59%
- Veröffentlicht 10.12.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:01:25
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort par...
CVE-2020-13525
- EPSS 1.59%
- Veröffentlicht 03.12.2020 18:15:10
- Zuletzt bearbeitet 21.11.2024 05:01:25
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticate...
CVE-2016-9045
- EPSS 0.58%
- Veröffentlicht 17.09.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:30
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter t...
CVE-2016-9048
- EPSS 0.18%
- Veröffentlicht 10.09.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:30
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks ...