CVE Browser

More filters (active)
CVE-2026-18409 HIGH

WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values

CVSS 7.2 EPSS 0.34% Aug 21, 2026
CVE-2026-10818 HIGH

WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

CVSS 8.1 EPSS 2.48% Jul 25, 2026
CVE-2020-36919 MEDIUM

WPForms 1.7.8 - Cross-Site Scripting (XSS)

CVSS 5.1 EPSS 0.37% Jan 13, 2026
CVE-2024-11273 MEDIUM

Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS

CVSS 6.1 EPSS 0.27% Mar 25, 2025
CVE-2024-11272 MEDIUM

Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS

CVSS 6.1 EPSS 0.27% Mar 25, 2025
CVE-2024-13403 MEDIUM

WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter

CVSS 6.4 EPSS 0.39% Feb 4, 2025
CVE-2024-56276 HIGH

WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability

CVSS 8.8 EPSS 0.39% Jan 7, 2025
CVE-2024-11223 MEDIUM

WPForms < 1.9.2.3 - Admin+ Stored XSS

CVSS 4.7 EPSS 0.52% Dec 26, 2024
CVE-2024-11205 HIGH

WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation

CVSS 8.5 EPSS 0.73% Dec 10, 2024
CVE-2024-7056 LOW

WPForms < 1.9.1.6 - Admin+ Stored XSS

CVSS 3.5 EPSS 0.47% Nov 25, 2024
CVE-2024-10593 MEDIUM

WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion

CVSS 4.3 EPSS 0.28% Nov 13, 2024
CVE-2023-52209 HIGH

WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerability

CVSS 8.0 EPSS 0.37% Aug 1, 2024
CVE-2023-7063 HIGH

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3…

CVSS 7.2 EPSS 0.53% Jan 20, 2024
CVE-2023-3213 MEDIUM

WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_page

CVSS 5.3 EPSS 0.51% Oct 4, 2023
CVE-2023-30500 MEDIUM

WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerability

CVSS 6.1 EPSS 0.40% Jun 22, 2023
CVE-2019-25145 HIGH

Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection

CVSS 7.2 EPSS 0.66% Jun 7, 2023
CVE-2022-3574 CRITICAL

WPForms Pro < 1.7.7 - CSV Injection

CVSS 9.8 EPSS 1.41% Nov 14, 2022
CVE-2020-10385 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

CVSS 5.4 EPSS 4.43% Mar 11, 2020

Showing 1 to 18 CVEs · page 1