Docuform

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 18
    Known Exploited: 0
    0
    Critical Level Threats
    9
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-51924

    An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component

    Last Modified: Aug 03, 2026
    Published: Jul 09, 2026

    CVE-2026-51923

    An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.

    Last Modified: Jul 28, 2026
    Published: Jul 09, 2026

    CVE-2026-51926

    An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.

    Last Modified: Jul 31, 2026
    Published: Jul 09, 2026

    CVE-2026-51925

    A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.

    Last Modified: Jul 31, 2026
    Published: Jul 09, 2026

    CVE-2025-61311

    A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Services (docuForm) v11.11c allows attackers to execute arbitrary Javascript in the context of a user's browser via injecting a crafted payload into an unfiltered variable value.

    Last Modified: May 12, 2026
    Published: May 11, 2026
    Items Per Page
    Docuform Vulnerabilities & Security CVEs | CVE-DB