American Financing operates web-facing mortgage and financial services applications, with the limited disclosure record centered on its email image upload and link request contact form components. The observed weakness patterns reflect web application input handling and form-processing concerns. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by American Financing over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3199HIGH Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image | Jun 12, 2007 | 7.5 | 29 | NO | YES |
CVE-2007-4499MEDIUM Unrestricted file upload vulnerability in output.php in American Financing eMail Image Upload 4.1 allows remote attackers to upload and execute arbitrary code via unspecified vecto | Aug 23, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by American Financing.
Media articles that mention a CVE ID that affects a product developed by American Financing — matched by CVE ID, not by vendor name.