apprain CVE Vulnerabilities & Metrics

Focus on apprain vulnerabilities and metrics.

Last updated: 10 Sep 2025, 22:25 UTC

About apprain Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with apprain. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total apprain CVEs: 32
Earliest CVE date: 23 Sep 2011, 23:55 UTC
Latest CVE date: 04 Sep 2025, 12:15 UTC

Latest CVE reference: CVE-2025-41063

Rolling Stats

30-day Count (Rolling): 32
365-day Count (Rolling): 32

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical apprain CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.84

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 32
4.0-6.9 3
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS apprain CVEs

These are the five CVEs with the highest CVSS scores for apprain, sorted by severity first and recency.

All CVEs for apprain

CVE-2025-41063 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 's' parameter in /apprain/developer/debug-log/db.

CVE-2025-41062 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in version 4.0.5 of appRain CMF, consisting of an authenticated reflected XSS due to a lack of proper validation of user input, through the 'page' parameter in /apprain/developer/addons.

CVE-2025-41061 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/uploadify.

CVE-2025-41060 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tree.

CVE-2025-41059 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/tablesorter.

CVE-2025-41058 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/row_manager.

CVE-2025-41057 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/rich_text_editor.

CVE-2025-41056 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/hysontable.

CVE-2025-41055 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/dialogs.

CVE-2025-41054 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/cycle.

CVE-2025-41053 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/commonresource.

CVE-2025-41052 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/canvasjs.

CVE-2025-41051 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/bootstrap.

CVE-2025-41050 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/base_libs.

CVE-2025-41049 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/appform.

CVE-2025-41048 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/admin.

CVE-2025-41047 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/ace.

CVE-2025-41046 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Addon][layouts]' and 'data[Addon][layouts_except]' parameters in /apprain/developer/addons/update/960grid.

CVE-2025-41045 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[sconfig][ethical_licensekey]' parameter in /apprain/admin/config/ethical.

CVE-2025-41044 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Page][name]' parameter in /apprain/page/manage-static-pages/create.

CVE-2025-41043 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[AppReportCode][id]' and 'data[AppReportCode][name]' parameters in /apprain/appreport/manage/.

CVE-2025-41042 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Option][message]', 'data[Option][subject]' and 'data[Option][templatetype]' parameters in /apprain/information/manage/emailtemplate/add.

CVE-2025-41041 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]' and 'data[title]' parameters in /apprain/developer/language/default.xml.

CVE-2025-41040 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]' and 'data[title]' parameters in /apprain/developer/language/lipsum.xml.

CVE-2025-41039 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[sconfig][admin_landing_page]', 'data[sconfig][currency]', 'data[sconfig][db_version]', 'data[sconfig][default_pagination]', 'data[sconfig][emailsetup_from_email]', 'data[sconfig][emailsetup_host]', 'data[sconfig][emailsetup_password]', 'data[sconfig][emailsetup_port]', 'data[sconfig][emailsetup_username]', 'data[sconfig][fileresource_id]', 'data[sconfig][large_image_height]', 'data[sconfig][large_image_width]' and 'data[sconfig][time_zone_padding]' parameters in /apprain/admin/config/opts.

CVE-2025-41038 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Group][name]' parameter in /apprain/admin/managegroup/add/.

CVE-2025-41037 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[FileManager][search]' parameter in /apprain/admin/filemanager.

CVE-2025-41036 apprain vulnerability CVSS: 0 04 Sep 2025, 12:15 UTC

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the  'data[Admin][description]', 'data[Admin][f_name]' and 'data[Admin][l_name]' parameters in /apprain/admin/account/edit.

CVE-2025-41035 apprain vulnerability CVSS: 0 04 Sep 2025, 11:15 UTC

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

CVE-2025-41034 apprain vulnerability CVSS: 0 04 Sep 2025, 11:15 UTC

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-static-pages/create/.

CVE-2025-41033 apprain vulnerability CVSS: 0 04 Sep 2025, 11:15 UTC

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create.

CVE-2025-41032 apprain vulnerability CVSS: 0 04 Sep 2025, 11:15 UTC

An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BAdmin%5D%5Busername%5D' parameter in /apprain/admin/manage/add/.

CVE-2013-6058 apprain vulnerability CVSS: 7.5 14 Nov 2013, 20:55 UTC

SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.

CVE-2011-5229 apprain vulnerability CVSS: 7.5 25 Oct 2012, 17:55 UTC

SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVE-2011-5228 apprain vulnerability CVSS: 4.3 25 Oct 2012, 17:55 UTC

Cross-site scripting (XSS) vulnerability in the Search module (quickstart/search) in appRain CMF 0.1.5 allows remote attackers to inject arbitrary web script or HTML via the ss parameter.

CVE-2012-1153 apprain vulnerability CVSS: 6.8 06 Oct 2012, 21:55 UTC

Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

CVE-2011-3704 apprain vulnerability CVSS: 5.0 23 Sep 2011, 23:55 UTC

appRain 0.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by cron.php.