Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Contact Form MEDIUM 6.1
CVE-2024-10646

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Fix: 5.2.7+
Fix from $1,600 2024-12-14
Contact Form MEDIUM 6.1
CVE-2024-9651

The Fluent Forms WordPress plugin before 5.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as adm…

Fix: 5.2.1+
Fix from $1,600 2024-12-09
Contact Form MEDIUM 5.4
CVE-2024-6703

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Fix: 5.1.20+
Fix from $1,600 2024-07-27
Contact Form HIGH 8.8
CVE-2024-4157

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection …

Fix: 5.1.16+
Fix from $1,950 2024-05-22
Contact Form MEDIUM 6.4
CVE-2024-4709

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Fix: 5.1.17+
Fix from $1,600 2024-05-18
Contact Form HIGH 7.5
CVE-2024-2782

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modifica…

Fix: 5.1.17+
Fix from $1,950 2024-05-18
Contact Form MEDIUM 5.4
CVE-2024-2772

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scr…

Fix: 5.1.14+
Fix from $1,600 2024-05-18
Contact Form CRITICAL 9.8
CVE-2024-2771

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation …

Fix: 5.1.17+
Fix from $2,300 2024-05-18
Contact Form MEDIUM 5.4
CVE-2023-6957

The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and in…

Fix: 5.1.10+
Fix from $1,600 2024-03-13
Contact Form CRITICAL 9.8
CVE-2023-24410

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contact Form - WPManageNinja LLC Contact Form P…

Fix: after 4.3.25
Fix from $2,300 2023-10-31
Contact Form MEDIUM 5.4
CVE-2023-0546

The Contact Form Plugin WordPress plugin before 4.3.25 does not properly sanitize and escape the srcdoc attribute in iframes in it's custom HTML fiel…

Fix: 4.3.25+
Fix from $1,600 2023-04-10
Contact Form CRITICAL 9.8
CVE-2022-3463

The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injec…

Fix: 4.3.13+
Fix from $2,300 2022-11-07
Contact Form HIGH 8.8
CVE-2021-34620

The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Site Scripting and limited Priv…

Fix: 3.6.67+
Fix from $1,950 2021-07-07