Machform is a web-based form-building platform whose vulnerability profile concentrates in a single product serving a significant role in online data collection and form submission workflows. The exposure recurs through application-layer input-handling and file-management weakness classes including cross-site scripting, SQL injection, unrestricted file uploads, cross-site request forgery, and path traversal; vulnerabilities affecting the product skew toward serious outcomes and frequently acquire public exploit code. Defenders should treat Machform instances as a patching priority, particularly in internet-exposed deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Machform over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6411CRITICAL An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is s | May 26, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6410CRITICAL An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter. | May 26, 2018 | 9.8 | 43 | NO | YES |
CVE-2018-6409MEDIUM An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on | May 26, 2018 | 5.3 | 35 | NO | YES |
CVE-2013-4948HIGH SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter. | Jul 29, 2013 | 7.5 | 35 | NO | YES |
CVE-2013-4949MEDIUM Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct reque | Jul 29, 2013 | 6.8 | 28 | NO | YES |
CVE-2024-37762CRITICAL MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. | Jul 1, 2024 | 9.9 | 27 | NO | NO |
CVE-2021-20102HIGH Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place. | Jun 29, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-20104HIGH Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php. | Jun 29, 2021 | 8.1 | 25 | NO | NO |
CVE-2024-37765HIGH Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page. | Jul 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2013-4950MEDIUM Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter. | Jul 29, 2013 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Machform.
Media articles that mention a CVE ID that affects a product developed by Machform — matched by CVE ID, not by vendor name.