Browse all 14 CVE security advisories affecting Newforma. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Newforma provides project information management software for architecture, engineering, and construction industries. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and authentication flaws. The platform has faced security incidents, including a 2021 vulnerability (CVE-2021-42312) allowing unauthorized access to project data. Security characteristics include integration with multiple third-party systems, increasing attack surface. While the company has addressed vulnerabilities through patches, the consistent presence of flaws in web interfaces and APIs suggests ongoing need for robust security testing in this specialized software sector.
This page lists every published CVE security advisory associated with Newforma. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.