Known Vulnerabilities for Processmaker by ProcessMaker
Listed below are 5 of the newest known vulnerabilities associated with "Processmaker" by "ProcessMaker".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-107803 json | ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in P... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2022-38577 json | Not Provided | 2022-09-19 | 2026-07-09 | |
| CVE-2020-13526 json | SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP reques... | 8.8 - HIGH | 2020-12-10 | 2022-06-07 |
| CVE-2020-13525 json | The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL inject... | 8.8 - HIGH | 2020-12-03 | 2022-06-07 |
| CVE-2016-9048 json | Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafte... | 7.4 - HIGH | 2018-09-10 | 2022-12-14 |
| CVE-2016-9045 json | A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can ... | 8.8 - HIGH | 2018-09-17 | 2022-12-14 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Processmaker | Processmaker | 3.4.11 | |||
| Application | Processmaker | Processmaker | 3.0.1.7 | |||
| Application | Processmaker | Processmaker | 3.0.1.7 |