Deliciousdays
Products
2- 12 CVEs
- 1 CVE
Recent CVEs
13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18570 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | ||
| CVE-2015-9333 | Cri | 0.64 | 9.8 | 0.02 | Aug 22, 2019 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. | ||
| CVE-2019-15238 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. | ||
| CVE-2014-10393 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The cforms2 plugin before 10.5 for WordPress has XSS. | ||
| CVE-2014-10392 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2019 | The cforms2 plugin before 10.2 for WordPress has XSS. | ||
| CVE-2017-18559 | Med | 0.40 | 6.1 | 0.01 | Aug 21, 2019 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. | ||
| CVE-2014-10377 | Med | 0.40 | 6.1 | 0.01 | Aug 21, 2019 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. | ||
| CVE-2023-52203 | Med | 0.38 | 5.9 | 0.00 | Jan 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. | ||
| CVE-2021-24322 | Med | 0.35 | 5.4 | 0.01 | Jun 1, 2021 | The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue. | ||
| CVE-2023-25449 | Med | 0.28 | 4.3 | 0.00 | Jun 15, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. | ||
| CVE-2014-9473 | 0.04 | — | 0.14 | Jan 8, 2015 | Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a… | |||
| CVE-2010-3977 | 0.03 | — | 0.04 | Nov 3, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters. | |||
| CVE-2008-0560 | 0.00 | — | 0.02 | Feb 4, 2008 | PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and… |
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
- risk 0.64cvss 9.8epss 0.02
The cforms2 plugin before 14.6.10 for WordPress has SQL injection.
- risk 0.57cvss 8.8epss 0.01
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
- risk 0.40cvss 6.1epss 0.01
The cforms2 plugin before 10.5 for WordPress has XSS.
- risk 0.40cvss 6.1epss 0.01
The cforms2 plugin before 10.2 for WordPress has XSS.
- risk 0.40cvss 6.1epss 0.01
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
- risk 0.40cvss 6.1epss 0.01
The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.
- risk 0.38cvss 5.9epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.
- risk 0.35cvss 5.4epss 0.01
The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.
- CVE-2014-9473Jan 8, 2015risk 0.04cvss —epss 0.14
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a…
- CVE-2010-3977Nov 3, 2010risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
- CVE-2008-0560Feb 4, 2008risk 0.00cvss —epss 0.02
PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and…