CVE-2023-27507: Microengine Mailform

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

Affected products

  • Microengine Mailform: from 1.1.0, before 1.1.9 (fixed in 1.1.9)

Published 2023-05-23. Last modified 2026-06-17.