VYPR

form-manager

by allpro

CVEs (2)

  • CVE-2024-36572CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

  • CVE-2015-7806CriOct 17, 2017
    risk 0.57cvss 9.8epss 0.06

    Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors.