Maarch develops a narrowly scoped suite of enterprise document and records management products, including Maarch RM, Letterbox, and GEC/GED platforms, serving niche regulatory and organizational archival roles. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability; the recurring weakness classes—SQL injection, authentication bypass, path traversal, and excessive authentication attempt failures—reflect the input-handling and access-control demands of web-facing document systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maarch over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1587HIGH Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by | Feb 19, 2015 | 7.5 | 61 | NO | YES |
CVE-2022-37772HIGH Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote at | Nov 23, 2022 | 7.5 | 28 | NO | NO |
CVE-2019-15855CRITICAL An issue was discovered in Maarch RM before 2.5. A path traversal vulnerability allows an unauthenticated remote attacker to overwrite any files with a crafted POST request if the | Jan 17, 2020 | 9.1 | 26 | NO | NO |
CVE-2022-37773MEDIUM An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the filter parameter, allows the complete disclosure of all databas | Nov 23, 2022 | 6.5 | 25 | NO | NO |
CVE-2019-15854HIGH An issue was discovered in Maarch RM before 2.5. A privilege escalation vulnerability allows an authenticated user with lowest privileges to give herself highest administration pri | Jan 17, 2020 | 8.8 | 25 | NO | NO |
CVE-2014-8995MEDIUM SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie. | Nov 20, 2014 | 5.0 | 23 | NO | YES |
CVE-2022-37774MEDIUM There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the app | Nov 23, 2022 | 5.3 | 22 | NO | NO |
CVE-2006-5492MEDIUM Unspecified vulnerability in Maerys Archive (Maarch) before 2.0.1 allows remote authenticated users to obtain sensitive information (document contents) via unspecified attack vecto | Oct 25, 2006 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maarch.
Media articles that mention a CVE ID that affects a product developed by Maarch — matched by CVE ID, not by vendor name.