VYPR

Gravity Forms

by Mediaburst

CVEs (3)

  • CVE-2023-2701MedJul 17, 2023
    risk 0.40cvss 6.1epss 0.00

    The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

  • CVE-2017-18495MedAug 13, 2019
    risk 0.40cvss 6.1epss 0.01

    The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.

  • CVE-2017-17780MedDec 20, 2017
    risk 0.33cvss 6.1epss 0.01

    The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor…