Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Maarch

First CVE: Oct 25, 2006Active for: 20 yearsTotal CVEs: 8

Maarch develops a narrowly scoped suite of enterprise document and records management products, including Maarch RM, Letterbox, and GEC/GED platforms, serving niche regulatory and organizational archival roles. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability; the recurring weakness classes—SQL injection, authentication bypass, path traversal, and excessive authentication attempt failures—reflect the input-handling and access-control demands of web-facing document systems. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Maarch over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2006
19 years ago
Most Recent CVE
Nov 23, 2022
1,339 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2015-1587HIGH
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by
Feb 19, 20157.561NOYES
CVE-2022-37772HIGH
Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote at
Nov 23, 20227.528NONO
CVE-2019-15855CRITICAL
An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the
Jan 17, 20209.126NONO
CVE-2022-37773MEDIUM
An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databas
Nov 23, 20226.525NONO
CVE-2019-15854HIGH
An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration pri
Jan 17, 20208.825NONO
CVE-2014-8995MEDIUM
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
Nov 20, 20145.023NOYES
CVE-2022-37774MEDIUM
There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the app
Nov 23, 20225.322NONO
CVE-2006-5492MEDIUM
Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (document contents) via unspecified attack vecto
Oct 25, 20064.014NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
38%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (62.5%)
Unknown3 (37.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High0 (0.0%)
Unknown3 (37.5%)
User Interaction
None5 (62.5%)
Unknown3 (37.5%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None3 (37.5%)
Unknown3 (37.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Maarch.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Maarch — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Maarch's Products

View all 1 CNAs →

Top CWEs