VYPR

Contact Forms by Cimatti

by Cimatti

CVEs (3)

  • CVE-2024-30549MedMar 31, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cimatti Contact Forms by Cimatti contact-forms.This issue affects Contact Forms by Cimatti: from n/a through <= 1.8.0.

  • CVE-2024-12184MedFeb 1, 2025
    risk 0.34cvss 5.3epss 0.00

    The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for…

  • CVE-2024-10521MedNov 27, 2024
    risk 0.21cvss 4.3epss 0.00

    The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for…