MicroengineCVEs & Vulnerabilities
2 CVEs affecting Microengine products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
2 CVEs→ All vendors
Most Affected Products
mailform 2
CVE-2023-27507CRITICAL
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
23 May 2023
9.8
CVSS
CVE-2023-27397CRITICAL
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
23 May 2023
9.8
CVSS
← PrevPage 1 / 1Next →