Vulnerabilities

Summary — last 7 days

New vulnerabilities2,532▼ 361 vs. last week
Critical / high1,338▲ 69 vs. last week
New active exploitation (KEV)6▼ 6 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

18 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.46%—Feuerhamster MailformAI6/15/20266/17/2026
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalyzedMedium (6.3)0.39%—Synck Mailform PRO CGI5/26/20256/17/2026
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
ModifiedHigh (7.5)0.89%—Synck Graphica Mailform PRO CGI8/25/20236/17/2026
Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi, estimate/estimate.js, search/search.js,…
ModifiedHigh (7.5)1.3%—Synck Mailform PRO CGI6/29/20236/17/2026
Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
ModifiedCritical (9.8)1.3%—Microengine Mailform5/23/20236/17/2026
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
ModifiedCritical (9.8)0.92%—Microengine Mailform5/23/20236/17/2026
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
ModifiedMedium (5.9)1.5%—Synck Mailform PRO CGI9/8/20226/17/2026
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.
ModifiedMedium (6.1)0.95%—Econosys-system PHP Mailform2/8/20226/17/2026
Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
ModifiedMedium (6.1)0.95%—Econosys-system PHP Mailform2/8/20226/17/2026
Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
ModifiedMedium (6.1)0.78%—Mailform01 Project Mailform015/24/20216/17/2026
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 July 27) allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModifiedCritical (9.8)2.3%—Mailform3/25/20206/17/2026
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
ModifiedMedium (6.1)0.77%—Mailform3/25/20206/17/2026
Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (6.8)2.3%—Synck Graphica Mailform PRO CGI2/27/20156/17/2026
SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModifiedMedium (4.3)0.93%—PHP Kobo Multifunctional Mailform Free7/20/20146/17/2026
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header.
ModifiedMedium (4.3)1.1%—H-fj Mailform Plugin1/4/20126/16/2026
Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedHigh (7.5)2.0%—Scripts.bdr130 Mailform10/9/20116/16/2026
PHP remote file inclusion vulnerability in index.php in MailForm 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.
ModifiedMedium (4.3)0.85%—Sebastian Winterhalder Mailform3/15/20106/16/2026
Cross-site scripting (XSS) vulnerability in the Mailform (mailform) extension before 0.9.24 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModifiedMedium (5)1.6%—Ranson Johnson Mailform11/14/20006/16/2026
mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.