p
processmaker
Security Risk Profile
40
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 10, 2018 to present
11
Total CVEs
7
Critical+High
0
Exploited
7
Unpatched
Threat Assessment
Avg CVSS
7.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
40/100
medium
🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
7Medium
4Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
4
2
XSS
2
3
Path Traversal
1
4
Code Injection
1
5
Malicious File Upload
1
Most Affected Products
1. ProcessMaker ProcessMaker10
2. ProcessMaker Open Source1
3. ProcessMaker pm4core-docker1
Recent Vulnerabilities
See more →CVE-2026-107803
CVSS 6.5medium
ProcessMaker has SQL injection in the tasks endpoint through the order_by parameter
Oct 9, 2026🔧 No Patch
CVE-2021-47978
CVSS 6.9medium
ProcessMaker 3.5.4 Local File Inclusion via Path Traversal
May 16, 2026🔧 No Patch
CVE-2013-10035
CVSS 8.7high
ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution
Jul 31, 2025🔧 No Patch
CVE-2025-34097
CVSS 8.6high
ProcessMaker < 3.5.4 Authenticated Plugin Upload RCE
Jul 10, 2025🔧 No Patch
CVE-2024-41453
CVSS 4.8medium
Jan 15, 2025🔧 No Patch
CVE-2024-25506
CVSS 6.5medium
Mar 28, 2024🔧 No Patch
CVE-2022-38577
CVSS 8.8high
Sep 19, 2022🔧 No Patch
CVE-2020-13526
CVSS 8.8high
Dec 10, 2020🔧 No Patch
CVE-2020-13525
CVSS 8.8high
Dec 3, 2020🔧 No Patch
CVE-2016-9045
CVSS 8.8high
Sep 17, 2018🔧 No Patch
Monitor processmaker in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.