Showing 2 vulnerabilities on this page for ProcessMaker

Signals CISA KEV Ransomware Nuclei
ProcessMaker vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ProcessMaker 3.5.4 Local File Inclusion via Path Traversal

ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication.

CWE-98May 16, 2026
CVSS6.9v4.0EPSS0.776%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

CWE-79Mar 28, 2024
CVSS6.5v3.1EPSS0.347%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX