Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
everest forms vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-24907
The Contact Form, Drag and Drop Form Builder for WordPress plugin prior to 1.8.0 does not escape the status parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
Wpeverest Everest Forms
4.8
CVSSv3
CVE-2023-51695
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! allows Stored XSS.This issue affects Everest Forms – B...
Wpeverest Everest Forms
9.8
CVSSv3
CVE-2019-13575
A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress up to and including 1.4.9. Successful exploitation of this vulnerability would allow a remote malicious user to execute arbitrary SQL commands on the affected system via includes/evf-entry-functi...
Wpeverest Everest Forms
NA
CVE-2024-1812
The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.0.7 via the 'font_url' parameter. This makes it possible for unauthenticated malicious users to make web requests to arbitrary locations originati...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started