Gravity Forms
by Mediaburst
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2701 | Med | 0.40 | 6.1 | 0.00 | Jul 17, 2023 | The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin. | ||
| CVE-2017-18495 | Med | 0.40 | 6.1 | 0.01 | Aug 13, 2019 | The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS. | ||
| CVE-2017-17780 | Med | 0.33 | 6.1 | 0.01 | Dec 20, 2017 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor… |
- risk 0.40cvss 6.1epss 0.00
The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
- risk 0.40cvss 6.1epss 0.01
The gravity-forms-sms-notifications plugin before 2.4.0 for WordPress has XSS.
- risk 0.33cvss 6.1epss 0.01
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor…