Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-32426 Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email n… Formie 2.1.44+ Fix from $1,6002025-04-11 MEDIUM 5.4 CVE-2025-32427 Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious c… Formie 2.1.44+ Fix from $1,6002025-04-11 MEDIUM 6.5 CVE-2020-13868 An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity. Comments 1.5.5+ Fix from $1,6002020-06-05 MEDIUM 5.4 CVE-2020-13869 An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name. Comments 1.5.5+ Fix from $1,6002020-06-05 MEDIUM 5.4 CVE-2020-13870 An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name. Comments 1.5.5+ Fix from $1,6002020-06-05 CRITICAL 9.1 CVE-2020-13485 The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header. Knock Knock 1.2.8+ Fix from $2,3002020-05-25 MEDIUM 6.1 CVE-2020-13486 The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. Knock Knock 1.2.8+ Fix from $1,6002020-05-25 HIGH 8.8 CVE-2020-13458 An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action. Image Resizer 2.0.9+ Fix from $1,9502020-05-25 MEDIUM 5.4 CVE-2020-13459 An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action. Image Resizer 2.0.9+ Fix from $1,6002020-05-25