Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wp Gravity Forms Freshdesk Plugin CRITICAL 9.8
CVE-2025-60089

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affect…

Fix: 1.3.6+
Fix from $2,300 2025-12-18
Wp Gravity Forms Insightly CRITICAL 9.8
CVE-2025-60090

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gr…

Fix: 1.1.7+
Fix from $2,300 2025-12-18
Wp Gravity Forms Zoho Crm And Bigin CRITICAL 9.8
CVE-2025-60091

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects W…

Fix: 1.3.0+
Fix from $2,300 2025-12-18
Wp Gravity Forms Constant Contact Plugin CRITICAL 9.8
CVE-2025-60174

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Object Injection.Thi…

Fix: after 1.1.2
Fix from $2,300 2025-12-18
Wp Gravity Forms Hubspot CRITICAL 9.8
CVE-2025-60178

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravit…

Fix: 1.2.7+
Fix from $2,300 2025-12-18
Wp Gravity Forms Salesforce CRITICAL 9.8
CVE-2025-60180

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue af…

Fix: 1.5.2+
Fix from $2,300 2025-12-18
Crm Perks Forms CRITICAL 9.8
CVE-2024-37463

Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects C…

Fix: 1.1.6+
Fix from $2,300 2024-11-01
Crm Perks Forms HIGH 7.2
CVE-2024-7484

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' f…

Fix: 1.1.4+
Fix from $1,950 2024-08-06
Crm Perks Forms MEDIUM 5.4
CVE-2024-30446

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.Thi…

Fix: 1.1.5+
Fix from $1,600 2024-03-29
Crm Perks Forms CRITICAL 10.0
CVE-2024-30498

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CR…

Fix: 1.1.5+
Fix from $2,300 2024-03-29
Crm Perks Forms HIGH 8.8
CVE-2024-30499

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CR…

Fix: 1.1.5+
Fix from $1,950 2024-03-29
Database For Contact Form 7\, Wpforms\, Elementor Forms HIGH 7.2
CVE-2024-1069

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function…

Fix: 1.3.3+
Fix from $1,950 2024-01-31
Database For Contact Form 7\, Wpforms\, Elementor Forms HIGH 7.8
CVE-2022-3604

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

Fix: 1.3.0+
Fix from $1,950 2024-01-16
Database For Contact Form 7\, Wpforms\, Elementor Forms MEDIUM 6.1
CVE-2023-31095

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja …

Fix: 1.2.9+
Fix from $1,600 2023-12-29
Integration For Salesforce And Contact Form 7\, Wpforms\, Elementor\, Ninja Forms MEDIUM 6.1
CVE-2023-37982

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Nin…

Fix: after 1.3.3
Fix from $1,600 2023-12-19
Integration For Woocommerce And Quickbooks MEDIUM 6.1
CVE-2023-38478

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and QuickBooks.This issue affects Integrat…

Fix: after 1.2.3
Fix from $1,600 2023-12-19
Integration For Woocommerce And Zoho Crm\, Books\, Invoice\, Inventory\, Bigin MEDIUM 6.1
CVE-2023-38481

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, B…

Fix: 1.3.7+
Fix from $1,600 2023-12-19
Integration For Constant Contact And Contact Form 7\, Wpforms\, Elementor\, Ninja MEDIUM 6.1
CVE-2023-47779

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks. Integration for Constant Contact and Contact Form 7, WPForms, Element…

Fix: 1.1.5+
Fix from $1,600 2023-12-07
Database For Contact Form 7\, Wpforms\, Elementor Forms CRITICAL 9.8
CVE-2023-31212

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms,…

Fix: after 1.3.0
Fix from $2,300 2023-10-31
Contact Form Entries Contact Form 7 Wpforms And More MEDIUM 5.4
CVE-2023-33311

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.

Fix: after 1.3.0
Fix from $1,600 2023-05-28
Integration For Contact Form 7 And Zoho Crm\, Bigin HIGH 8.8
CVE-2023-25976

Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin plugin <= 1.2.2 versions.

Fix: after 1.2.2
Fix from $1,950 2023-05-26
Crm Perks Forms MEDIUM 6.1
CVE-2022-38467

Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

Fix: after 1.1.0
Fix from $1,600 2023-01-14
Contact Form Entries MEDIUM 6.1
CVE-2021-25079EPSS 7%

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, ord…

Fix: 1.2.4+
Fix from $1,600 2022-01-24
Contact Form Entries MEDIUM 6.1
CVE-2021-25080EPSS 84%

The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP …

Fix: 1.1.7+
Fix from $1,600 2022-01-24