VYPR

Quform

by WordPress

CVEs (2)

  • CVE-2024-8756MedNov 9, 2024
    risk 0.34cvss 5.3epss 0.00

    The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the 'saveUploadedFile' function. This makes it possible for unauthenticated attackers to extract sensitive data, such as…

  • CVE-2026-56058CriJun 26, 2026
    risk 0.00cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.