Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Matcha Invoice HIGH 7.2
CVE-2026-33273

Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, an arbitrary fi…

Fix: after 2.6.6
Fix from $1,950 2026-04-08
Matcha Sns MEDIUM 5.4
CVE-2026-27787

Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on…

Fix: after 1.3.9
Fix from $1,600 2026-04-08
Matcha Invoice HIGH 8.8
CVE-2026-24913

SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information stored in the database may be…

Fix: after 2.6.6
Fix from $1,950 2026-04-08
Matchasns MEDIUM 6.5
CVE-2015-5645

ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Matchasns MEDIUM 6.8
CVE-2015-5644

The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code vi…

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Matchasns MEDIUM 6.8
CVE-2015-5643

The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP cod…

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Matchasns MEDIUM 6.5
CVE-2015-5642

Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unsp…

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Sencha Sns MEDIUM 6.8
CVE-2012-1237

Cross-site request forgery (CSRF) vulnerability in SENCHA SNS before 1.0.2 allows remote attackers to hijack the authentication of arbitrary users.

Fix: after 1.0.1
Fix from $1,600 2012-04-06