Home/Product/apprain
Product

apprain

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-58279
all versions
appRain CMF 4.0.5 contains an authenticated remote code execution vulnerability that allows administrative users to upload malicio
8.8HIGH
CVE-2025-41063
all versions
A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of
5.4MEDIUM
CVE-2025-41062
all versions
A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of
5.4MEDIUM
CVE-2025-41061
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41060
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41059
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41058
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41057
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41056
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41055
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41054
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41053
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41052
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41051
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41050
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41049
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41048
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41047
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41046
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41045
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41044
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41043
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41042
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41041
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41040
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41039
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41038
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41037
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41036
all versions
A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper
5.4MEDIUM
CVE-2025-41035
all versions
A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ all
6.5MEDIUM
CVE-2025-41034
all versions
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, upd
9.8CRITICAL
CVE-2025-41033
all versions
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, upd
9.8CRITICAL
CVE-2025-41032
all versions
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, upd
9.8CRITICAL
CVE-2013-6058
<= 3.0.2
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PAT
CVE-2011-5229
all versions
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to ex
CVE-2011-5228
all versions
Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to
CVE-2012-1153
<= 0.1.5
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers
CVE-2011-3704
all versions
appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the insta
threatengine.sh