Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
formidable vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2022-29622
An arbitrary file upload vulnerability in formidable v3.1.4 allows malicious users to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Al...
Formidable Project Formidable 3.1.4
1 Github repository
NA
CVE-2023-1405
The Formidable Forms WordPress plugin prior to 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
Strategy11 Formidable Forms
NA
CVE-2024-0660
The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the up...
Strategy11 Formidable Forms
NA
CVE-2023-28663
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.
Formidablepro2pdf Formidable Pro2pdf
NA
CVE-2023-2877
The Formidable Forms WordPress plugin prior to 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions ...
Strategy11 Formidable Forms
1 Github repository
3.5
CVSSv2
CVE-2021-24608
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin prior to 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capabili...
Strategy11 Formidable Form Builder
6.8
CVSSv2
CVE-2021-24884
The Formidable Form Builder WordPress plugin prior to 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote malicious user to exploit a HTML-injection byinjecting a malicous ...
Strategy11 Formidable Form Builder
2 Github repositories
7.5
CVSSv2
CVE-2019-15780
The formidable plugin prior to 4.02.01 for WordPress has unsafe deserialization.
Strategy11 Formidable Form Builder
NA
CVE-2023-0816
The Formidable Forms WordPress plugin prior to 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
Strategy11 Formidable Form Builder
NA
CVE-2023-6830
The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Pa...
Strategy11 Formidable Form Builder
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
deserialization
CVE-2024-4040
cross-site scripting
CVE-2023-25790
CVE-2024-2961
XML external entity
CVE-2024-26926
CVE-2024-32806
CVE-2024-32711
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »