Processmaker

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47978

    ProcessMaker 3.5.4 Local File Inclusion via Path Traversal

    Last Modified: May 18, 2026
    Published: May 16, 2026

    CVE-2013-10035

    ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution

    Last Modified: Apr 15, 2026
    Published: Jul 31, 2025

    CVE-2025-34097

    ProcessMaker < 3.5.4 Authenticated Plugin Upload RCE

    Last Modified: Apr 15, 2026
    Published: Jul 10, 2025

    CVE-2022-38577

    ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators.

    Last Modified: Jun 03, 2025
    Published: Sep 19, 2022

    CVE-2020-13526

    SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.

    Last Modified: Nov 21, 2024
    Published: Dec 10, 2020
    Items Per Page