Pmachine is a content-management and publishing platform with a modest footprint spanning products such as Pmachine Pro, Pmachine Free, and ExpressionEngine, primarily targeting web publishers and small-to-medium sites. The recurring signal in its disclosed vulnerabilities centers on input-handling and cross-site scripting weaknesses inherent to web-application templates and form processing. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pmachine over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1086HIGH PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote attackers to execute arbitrary PHP code by modifying the pm_ | Jun 17, 2003 | 7.5 | 34 | NO | YES |
CVE-2005-0513HIGH PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remot | Feb 19, 2005 | 7.5 | 30 | NO | YES |
CVE-2006-0461MEDIUM Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer). | Jan 27, 2006 | 4.3 | 21 | NO | YES |
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_ | Jan 17, 2008 | 2.6 | 18 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pmachine.
Media articles that mention a CVE ID that affects a product developed by Pmachine — matched by CVE ID, not by vendor name.