CVE Browser

CVE-2026-9187 MEDIUM

Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter

CVSS 5.3 EPSS 0.39% Jun 16, 2026
CVE-2026-5693 MEDIUM

Smart Appointment & Booking <= 1.0.8 - Missing Authorization to Unauthenticated Arbitrary Booking Cancellation

CVSS 5.3 EPSS 0.39% May 12, 2026
CVE-2026-0742 MEDIUM

Smart Appointment & Booking <= 1.0.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting via saab_save_form_data AJAX Action

CVSS 6.4 EPSS 0.30% Feb 4, 2026
CVE-2025-12825 MEDIUM

User Registration Using Contact Form 7 <= 2.5 - Authenticated (Subscriber+) Information Exposure

CVSS 5.3 EPSS 0.61% Jan 17, 2026
CVE-2025-12834 MEDIUM

Accept Stripe Payments Using Contact Form 7 <= 3.1 - Reflected Cross-Site Scripting via failure_message

CVSS 6.1 EPSS 0.25% Dec 12, 2025
CVE-2025-2883 MEDIUM

Accept SagePay Payments Using Contact Form 7 <= 2.0 - Unauthenticated Information Exposure

CVSS 5.3 EPSS 0.40% Apr 8, 2025
CVE-2024-12250 MEDIUM

Accept Authorize.NET Payments Using Contact Form 7 <= 2.2 - Unauthenticated Information Exposure

CVSS 5.3 EPSS 0.39% Dec 18, 2024
CVE-2024-12255 MEDIUM

Accept Stripe Payments Using Contact Form 7 <= 2.5 - Unauthenticated Information Exposure

CVSS 5.3 EPSS 0.52% Dec 12, 2024
CVE-2024-6316 HIGH

Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Upload

CVSS 8.8 EPSS 0.52% Jul 9, 2024
CVE-2024-6317 HIGH

Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion

CVSS 8.8 EPSS 0.60% Jul 9, 2024

Showing 1 to 10 CVEs · page 1