Marmind's vulnerability footprint is centered on its web and collaboration platform, with recurring issues in application-layer input handling and access control, including cross-site scripting, CSV formula injection, and authorization weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marmind over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26507HIGH A CSV Injection (also known as Formula Injection) vulnerability in the Marmind web application with version 4.1.141.0 allows malicious users to gain remote control of other compute | Nov 5, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-26505MEDIUM A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimat | Nov 5, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-26506MEDIUM An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative u | Nov 5, 2020 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marmind.
Media articles that mention a CVE ID that affects a product developed by Marmind — matched by CVE ID, not by vendor name.