Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2025-4208 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up t… Nex Forms after 8.9.2 Fix from $1,6002025-05-08 MEDIUM 5.4 CVE-2025-3468 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the clean_h… Nex Forms 8.9.2+ Fix from $1,6002025-05-08 HIGH 7.2 CVE-2024-53808 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-build… Nex Forms 8.7.9+ Fix from $1,9502024-12-06 MEDIUM 6.1 CVE-2024-47389 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-build… Nex Forms 8.7.4+ Fix from $1,6002024-10-05 MEDIUM 5.4 CVE-2024-37512 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder … Nex Forms 8.6.1+ Fix from $1,6002024-07-21 MEDIUM 5.4 CVE-2024-25593 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows … Nex Forms 8.5.6+ Fix from $1,6002024-03-15 HIGH 8.8 CVE-2023-52120 Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms – Ultimate Form Builder – Contact forms and much more.This issue affects NEX-Forms… Nex Forms after 8.5.2 Fix from $1,9502024-01-05 HIGH 7.2 CVE-2023-50838 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder – Conta… Nex Forms after 8.5.5 Fix from $1,9502023-12-28 MEDIUM 5.4 CVE-2023-0439 The NEX-Forms WordPress plugin before 8.4.4 does not escape its form name, which could lead to Stored Cross-Site Scripting issues. By default only Su… Nex Forms 8.4.4+ Fix from $1,6002023-07-17 HIGH 7.2 CVE-2023-2114EPSS 45% The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it… Nex Forms 8.4+ Fix from $1,9502023-05-08 MEDIUM 5.4 CVE-2023-0272 The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post … Nex Forms 8.3.3+ Fix from $1,6002023-03-27 MEDIUM 6.3 CVE-2020-36670 The NEX-Forms. plugin for WordPress is vulnerable to unauthorized disclosure and modification of data in versions up to, and including 7.7.1 due to m… Nex Forms after 7.7.1 Fix from $1,6002023-03-07 HIGH 8.8 CVE-2022-3142EPSS 11% The NEX-Forms WordPress plugin before 7.9.7 does not properly sanitise and escape user input before using it in SQL statements, leading to SQL inject… Nex Forms 7.9.7+ Fix from $1,9502022-09-19 HIGH 7.5 CVE-2021-34675 Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. Nex Forms after 7.8.7 Fix from $1,9502021-07-19 HIGH 7.5 CVE-2021-34676 Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation. Nex Forms after 7.8.7 Fix from $1,9502021-07-19 CRITICAL 9.8 CVE-2015-9452 The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id… Nex Forms 4.6.1+ Fix from $2,3002019-10-07