Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-36919 WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scr… Wpforms after 1.7.8 Fix from $1,6002026-01-13 MEDIUM 6.1 CVE-2024-11272 The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which co… Pirate Forms 2.6.0+ Fix from $1,6002025-03-25 MEDIUM 6.1 CVE-2024-11273 The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which co… Contact Form 2.6.0+ Fix from $1,6002025-03-25 MEDIUM 5.4 CVE-2024-13403 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site… Wpforms 1.9.3.2+ Fix from $1,6002025-02-04 HIGH 8.8 CVE-2024-56276 Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Secur… Wpforms 1.9.2.3+ Fix from $1,9502025-01-07 MEDIUM 6.5 CVE-2024-11205 The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' … Wpforms 1.9.2.2+ Fix from $1,6002024-12-10 MEDIUM 6.1 CVE-2023-7063 The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including… Wpforms after 1.8.5.3 Fix from $1,6002024-01-20 MEDIUM 5.3 CVE-2023-3213 The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page functio… Wp Mail Smtp after 3.8.0 Fix from $1,6002023-10-04 MEDIUM 6.1 CVE-2023-30500 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 v… Contact Form after 1.8.1.2 Fix from $1,6002023-06-22 MEDIUM 6.1 CVE-2019-25145 The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file … Contact Form after 2.5.1 Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2022-3574 The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. Wpforms Pro 1.7.7+ Fix from $2,3002022-11-14 MEDIUM 5.4 CVE-2020-10385 A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. Contact Form 1.5.9+ Fix from $1,6002020-03-24