CVE-2023-32623: 2inc Snow Monkey Forms

Critical severity, CVSS 9.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.

Affected products

  • 2inc Snow Monkey Forms: before 5.1.2 (fixed in 5.1.2)

Published 2023-06-28. Last modified 2026-06-17.