ProcessMaker develops a business process management and workflow automation platform that, despite a narrow product portfolio, operates in environments where process execution and data handling are central to operations. The recurring vulnerability signal centers on data-layer and deserialization issues—SQL injection, untrusted deserialization, and improper permission preservation—that reflect the platform's role in processing and orchestrating sensitive workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Processmaker over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38577HIGH ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. | Sep 19, 2022 | 8.8 | 31 | NO | NO |
CVE-2016-9045HIGH A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in P | Sep 17, 2018 | 8.8 | 29 | NO | NO |
CVE-2021-47978MEDIUM ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Att | May 16, 2026 | 6.2 | 26 | NO | NO |
CVE-2020-13525HIGH The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP re | Dec 3, 2020 | 8.8 | 26 | NO | NO |
CVE-2016-9048HIGH Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker ca | Sep 10, 2018 | 7.4 | 23 | NO | NO |
CVE-2020-13526HIGH SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and | Dec 10, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Processmaker.
Media articles that mention a CVE ID that affects a product developed by Processmaker — matched by CVE ID, not by vendor name.