Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
forms vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2020-36173
The Ninja Forms plugin prior to 3.4.28 for WordPress lacks escaping for submissions-table fields.
Ninjaforms Ninja Forms
6.5
CVSSv3
CVE-2020-36174
The Ninja Forms plugin prior to 3.4.27.1 for WordPress allows CSRF via services integration.
Ninjaforms Ninja Forms
5.3
CVSSv3
CVE-2020-36175
The Ninja Forms plugin prior to 3.4.27.1 for WordPress allows malicious users to bypass validation via the email field.
Ninjaforms Ninja Forms
4.8
CVSSv3
CVE-2018-7747
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin prior to 1.6.0-rc.1 for WordPress allow remote malicious users to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported fo...
Calderalabs Caldera Forms
1 EDB exploit
1 Github repository
5.4
CVSSv3
CVE-2021-4367
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Options Change by using the flo_import_forms_options AJAX action in versions up to, and including, 1.0.35 due to insufficient input sanitization and outpu...
Flothemes Flo Forms
5.4
CVSSv3
CVE-2022-36791
Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Awesome UG Torro Forms plugin <= 1.0.16 at WordPress.
Awesome Torro Forms
6.1
CVSSv3
CVE-2022-0879
The Caldera Forms WordPress plugin prior to 1.9.7 does not validate and escape the cf-api parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Calderaforms Caldera Forms
7.5
CVSSv3
CVE-2023-1405
The Formidable Forms WordPress plugin prior to 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
Strategy11 Formidable Forms
9.8
CVSSv3
CVE-2015-9301
The liveforms plugin prior to 3.2.0 for WordPress has SQL injection.
W3eden Live Forms
6.1
CVSSv3
CVE-2019-2886
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Services). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful ...
Oracle Forms 12.2.1.3.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »