Cformsii Project / Cformsii
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-52203 | WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 5.9 | Jan 8, 2024 |
| CVE-2023-25449 | WordPress CformsII Plugin <=15.0.4 is vulnerable to Cross Site Request Forgery (CSRF) | HIGH | 8.8 | Jun 15, 2023 |
| CVE-2014-10393 | The cforms2 plugin before 10.5 for WordPress has XSS. | MEDIUM | 6.1 | Aug 22, 2019 |
| CVE-2014-10392 | The cforms2 plugin before 10.2 for WordPress has XSS. | MEDIUM | 6.1 | Aug 22, 2019 |
| CVE-2015-9333 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. | CRITICAL | 9.8 | Aug 22, 2019 |
| CVE-2017-18570 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | CRITICAL | 9.8 | Aug 22, 2019 |
| CVE-2017-18559 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. | MEDIUM | 6.1 | Aug 21, 2019 |
| CVE-2014-10377 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. | MEDIUM | 6.1 | Aug 21, 2019 |
| CVE-2019-15238 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | HIGH | 8.8 | Aug 20, 2019 |
Showing 1 to 9 of 9 CVEs