CVE-2023-27397: Microengine Mailform

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

Affected products

  • Microengine Mailform: from 1.1.0, before 1.1.9 (fixed in 1.1.9)

Published 2023-05-23. Last modified 2026-06-17.