VYPR

Vendor CVEs

Bestwebsoft

All CVEs

81 total · sorted by risk
  • CVE-2017-18501MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.

  • CVE-2017-18500MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The social-buttons-pack plugin before 1.1.1 for WordPress has multiple XSS issues.

  • CVE-2017-2171MedMay 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom…

  • CVE-2023-28778MedJun 22, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Pagination plugin <= 1.2.2 versions.

  • CVE-2023-0764MedApr 17, 2023
    risk 0.35cvss 5.4epss 0.00

    The Gallery by BestWebSoft WordPress plugin before 4.7.0 does not perform proper sanitization of gallery information, leading to a Stored Cross-Site Scription vulnerability. The attacker must have at least the privileges of the Author role.

  • CVE-2021-24966MedMar 14, 2022
    risk 0.35cvss 4.9epss 0.05

    The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

  • CVE-2024-2200MedApr 9, 2024
    risk 0.33cvss 6.1epss 0.01

    The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2024-3112MedJul 12, 2024
    risk 0.31cvss 4.8epss 0.00

    The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

  • CVE-2023-36527MedNov 7, 2023
    risk 0.31cvss 4.7epss 0.01

    Improper Neutralization of Formula Elements in a CSV File vulnerability in BestWebSoft Post to CSV by BestWebSoft.This issue affects Post to CSV by BestWebSoft: from n/a through 1.4.0.

  • CVE-2022-44734MedApr 16, 2023
    risk 0.31cvss 4.8epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 versions.

  • CVE-2025-63056MedDec 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.6.

  • CVE-2023-4469MedOct 6, 2023
    risk 0.27cvss 5.3epss 0.00

    The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to…

  • CVE-2017-20055LowJun 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2012-10017MedDec 26, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 2.06…

  • CVE-2012-10015MedMay 31, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in BestWebSoft Twitter Plugin up to 2.14 on WordPress. It has been classified as problematic. Affected is the function twttr_settings_page of the file twitter.php of the component Settings Page. The manipulation leads to cross-site request forgery. It…

  • CVE-2014-125102MedMay 29, 2023
    risk 0.21cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Thumbnail Handler. The manipulation leads to information disclosure. The attack can be…

  • CVE-2012-10012MedApr 10, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in BestWebSoft Facebook Like Button up to 2.13 and classified as problematic. Affected by this vulnerability is the function fcbk_bttn_plgn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross-site request forgery.…

  • CVE-2012-10010MedApr 9, 2023
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.…

  • CVE-2015-10127LowDec 26, 2023
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was found in PlusCaptcha Plugin up to 2.0.6 on WordPress and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.14 is able…

  • CVE-2014-125109LowDec 26, 2023
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.27. It has been declared as problematic. This vulnerability affects the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site…

  • CVE-2014-125100LowMay 2, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address…

  • CVE-2014-125097LowApr 10, 2023
    risk 0.16cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in BestWebSoft Facebook Like Button up to 2.33. Affected is the function fcbkbttn_settings_page of the file facebook-button-plugin.php. The manipulation leads to cross site scripting. It is possible to launch the…

  • CVE-2014-125095LowApr 9, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site…

  • CVE-2013-10022LowApr 5, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site…

  • CVE-2014-125103LowMay 31, 2023
    risk 0.09cvss 2.4epss 0.01

    A vulnerability was found in BestWebSoft Twitter Plugin up to 1.3.2 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function twttr_settings_page of the file twitter.php. The manipulation of the argument…

  • CVE-2007-3199Jun 12, 2007
    risk 0.03cvss epss 0.03

    Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension and an image content type, as demonstrated by image/jpeg.

  • CVE-2015-0890Mar 3, 2015
    risk 0.00cvss epss 0.02

    The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

  • CVE-2014-9283Mar 3, 2015
    risk 0.00cvss epss 0.02

    The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

  • CVE-2014-8320Oct 17, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the "Label text" field to the results…

  • CVE-2006-6994Feb 12, 2007
    risk 0.00cvss epss 0.02

    Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers to upload and execute arbitrary ASP files by removing the client-side security checks.

  • CVE-2006-5598Oct 28, 2006
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php for GOOP Gallery 2.0, and possibly other versions before 2.0.3, allows remote attackers to inject arbitrary HTML or web script via the image parameter.

Page 2 of 2