Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-3247
The Contact Form 7 plugin for WordPress is vulnerable to Order Replay in all versions up to, and including, 6.0.5 via the 'wpcf7_stripe_skip_spam_che…
Contact Form 7
6.0.6+
MEDIUM 6.1
CVE-2024-4704
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their…
Contact Form 7
5.9.5+
MEDIUM 6.1
CVE-2024-2242
The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter in all versions up to, and inc…
Contact Form 7
5.9.2+
HIGH 7.2
CVE-2023-6449
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function a…
Contact Form 7
5.8.4+
CRITICAL 9.8
CVE-2023-40609
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom valida…
Contact Form 7 Custom Validation
Mitigation only
HIGH 8.8
CVE-2021-24159
Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScr…
Contact Form 7
after 3.1.9
CRITICAL 10.0
CVE-2020-35489EPSS 89%
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filenam…
Contact Form 7
5.3.2+
CRITICAL 9.8
CVE-2018-20979
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
Contact Form 7
5.0.4+
MEDIUM 5.0
CVE-2014-2265
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omittin…
Contact Form 7
after 3.7.1