Apprain is a modestly represented vendor whose vulnerability exposure concentrates in a single, widely deployed application product; despite a narrow product footprint, the vendor ranks among the more prominent in the landscape. Vulnerabilities affecting Apprain skew toward serious outcomes with a meaningful share reaching critical severity, and the disclosure history shows a notable tendency toward public exploit code availability. The exposure recurs through application-layer weakness classes including cross-site scripting, SQL injection, path traversal, and information disclosure—patterns endemic to web-facing software where input validation and access control shortfalls propagate directly to end users. Defenders should treat Apprain application instances as high-priority for patching, particularly in internet-facing contexts. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apprain over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1153MEDIUM Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with | Oct 6, 2012 | 6.8 | 56 | NO | YES |
CVE-2025-41033CRITICAL An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5B | Sep 4, 2025 | 9.8 | 33 | NO | NO |
CVE-2011-5229HIGH SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO. | Oct 25, 2012 | 7.5 | 32 | NO | YES |
CVE-2024-58279HIGH appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicious PHP files through the filemanager upload endpoi | Dec 10, 2025 | 8.8 | 28 | NO | NO |
CVE-2013-6058HIGH SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/. | Nov 14, 2013 | 7.5 | 28 | NO | YES |
CVE-2025-41034CRITICAL An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5B | Sep 4, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-41032CRITICAL An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5B | Sep 4, 2025 | 9.8 | 27 | NO | NO |
CVE-2011-5228MEDIUM Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss par | Oct 25, 2012 | 4.3 | 25 | NO | YES |
CVE-2025-41035MEDIUM A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityMa | Sep 4, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-41061MEDIUM A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon | Sep 4, 2025 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apprain.
Media articles that mention a CVE ID that affects a product developed by Apprain — matched by CVE ID, not by vendor name.