CVE-2023-27507: Microengine Mailform
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
Affected products
- Microengine Mailform: from 1.1.0, before 1.1.9 (fixed in 1.1.9)
Published 2023-05-23. Last modified 2026-06-17.