VYPR
Vendor

Deliciousdays

Products
2
CVEs
13
Across products
13
Status
Private

Products

2

Recent CVEs

13
  • CVE-2017-18570CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

  • CVE-2015-9333CriAug 22, 2019
    risk 0.64cvss 9.8epss 0.02

    The cforms2 plugin before 14.6.10 for WordPress has SQL injection.

  • CVE-2019-15238HigAug 20, 2019
    risk 0.57cvss 8.8epss 0.01

    The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.

  • CVE-2014-10393MedAug 22, 2019
    risk 0.40cvss 6.1epss 0.01

    The cforms2 plugin before 10.5 for WordPress has XSS.

  • CVE-2014-10392MedAug 22, 2019
    risk 0.40cvss 6.1epss 0.01

    The cforms2 plugin before 10.2 for WordPress has XSS.

  • CVE-2017-18559MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.

  • CVE-2014-10377MedAug 21, 2019
    risk 0.40cvss 6.1epss 0.01

    The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php.

  • CVE-2023-52203MedJan 8, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.

  • CVE-2021-24322MedJun 1, 2021
    risk 0.35cvss 5.4epss 0.01

    The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue.

  • CVE-2023-25449MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.

  • CVE-2014-9473Jan 8, 2015
    risk 0.04cvss epss 0.14

    Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the cf_uploadfile2[] parameter, then accessing the file via a…

  • CVE-2010-3977Nov 3, 2010
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

  • CVE-2008-0560Feb 4, 2008
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and…