VYPR

Matchasns

by Icz

CVEs (5)

  • CVE-2026-27787MedApr 8, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in MATCHA SNS 1.3.9 and earlier. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the website using the product.

  • CVE-2015-5645Oct 6, 2015
    risk 0.00cvss epss 0.01

    ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.

  • CVE-2015-5644Oct 6, 2015
    risk 0.00cvss epss 0.01

    The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.

  • CVE-2015-5643Oct 6, 2015
    risk 0.00cvss epss 0.01

    The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.

  • CVE-2015-5642Oct 6, 2015
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.