CVE-2023-28413: Snow Monkey Forms Project Snow Monkey Forms

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

Affected products

Published 2023-05-23. Last modified 2026-06-17.