Formcraft
Ncrafts · 10 CVEs
FormCraft <= 3.9.11 - Missing Authorization to Plugin Data Export in formcraft-main.php
Feb 18, 2025
FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload
Feb 18, 2025
WordPress FormCraft – Contact Form Builder for WordPress plugin <= 1.2.7 - Broken Access Control vulnerability
Dec 9, 2024
WordPress FormCraft plugin <= 1.2.10 - Broken Access Control vulnerability
Nov 1, 2024
FormCraft Premium < 3.9.7 - Admin+ SQLi
Jun 27, 2023
WordPress FormCraft Plugin <= 1.2.6 is vulnerable to Cross Site Scripting (XSS)
May 15, 2023
FormCraft Basic < 1.2.6 - Admin+ Stored Cross Site Scripting
Jun 6, 2022
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
Sep 10, 2019
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
Aug 16, 2019
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the au…
Mar 12, 2019
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers…
Dec 20, 2013
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-13783 | FormCraft <= 3.9.11 - Missing Authorization to Plugin Data Export in formcraft-main.php | MEDIUM | 0.41% | Feb 18, 2025 |
| CVE-2025-0817 | FormCraft - Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload | HIGH | 0.35% | Feb 18, 2025 |
| CVE-2023-47823 | WordPress FormCraft – Contact Form Builder for WordPress plugin <= 1.2.7 - Broken Access Control vulnerability | MEDIUM | 0.38% | Dec 9, 2024 |
| CVE-2024-43157 | WordPress FormCraft plugin <= 1.2.10 - Broken Access Control vulnerability | MEDIUM | 0.39% | Nov 1, 2024 |
| CVE-2023-2592 | FormCraft Premium < 3.9.7 - Admin+ SQLi | HIGH | 0.85% | Jun 27, 2023 |
| CVE-2023-22717 | WordPress FormCraft Plugin <= 1.2.6 is vulnerable to Cross Site Scripting (XSS) | MEDIUM | 0.36% | May 15, 2023 |
| CVE-2022-1647 | FormCraft Basic < 1.2.6 - Admin+ Stored Cross Site Scripting | MEDIUM | 0.59% | Jun 6, 2022 |
| CVE-2017-18600 | The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. | MEDIUM | 0.70% | Sep 10, 2019 |
| CVE-2019-15114 | The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. | HIGH | 0.67% | Aug 16, 2019 |
| CVE-2019-5920 | Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a spe… | HIGH | 0.83% | Mar 12, 2019 |
| CVE-2013-7187 | SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via t… | HIGH | 4.78% | Dec 20, 2013 |
Showing 1 to 10 of 10 CVEs