Synck Graphica develops a narrow line of web-based CGI applications, with observed vulnerabilities clustering around MailForm Pro and Download Log utilities that feature path-traversal and input-validation weaknesses. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Synck Graphica over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-40599HIGH Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-o | Aug 25, 2023 | 7.5 | 22 | NO | NO |
CVE-2015-0883MEDIUM SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary cod | Feb 27, 2015 | 6.8 | 20 | NO | NO |
CVE-2015-0867MEDIUM Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename. | Jan 21, 2015 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Synck Graphica.
Media articles that mention a CVE ID that affects a product developed by Synck Graphica — matched by CVE ID, not by vendor name.