Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Formie MEDIUM 5.4
CVE-2025-32426

Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email n…

Fix: 2.1.44+
Fix from $1,600 2025-04-11
Formie MEDIUM 5.4
CVE-2025-32427

Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious c…

Fix: 2.1.44+
Fix from $1,600 2025-04-11
Comments MEDIUM 6.5
CVE-2020-13868

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.

Fix: 1.5.5+
Fix from $1,600 2020-06-05
Comments MEDIUM 5.4
CVE-2020-13869

An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.

Fix: 1.5.5+
Fix from $1,600 2020-06-05
Comments MEDIUM 5.4
CVE-2020-13870

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

Fix: 1.5.5+
Fix from $1,600 2020-06-05
Knock Knock CRITICAL 9.1
CVE-2020-13485

The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

Fix: 1.2.8+
Fix from $2,300 2020-05-25
Knock Knock MEDIUM 6.1
CVE-2020-13486

The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.

Fix: 1.2.8+
Fix from $1,600 2020-05-25
Image Resizer HIGH 8.8
CVE-2020-13458

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.

Fix: 2.0.9+
Fix from $1,950 2020-05-25
Image Resizer MEDIUM 5.4
CVE-2020-13459

An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.

Fix: 2.0.9+
Fix from $1,600 2020-05-25