VYPR
Vendor

Mw Wp Form Project

Products
6
CVEs
38
Across products
54
Status
Private

Products

6

Recent CVEs

38
View all 38 CVEs →
  • CVE-2023-6316CriJan 11, 2024
    risk 0.57cvss 9.8epss 0.01

    The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on…

  • CVE-2026-5436HigApr 8, 2026
    risk 0.46cvss 8.1epss 0.01

    The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's…

  • CVE-2026-4347HigApr 2, 2026
    risk 0.46cvss 8.1epss 0.01

    The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for…

  • CVE-2024-24804MedFeb 10, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Form allows Stored XSS.This issue affects MW WP Form: from n/a through 5.0.6.

  • CVE-2023-6559HigDec 16, 2023
    risk 0.42cvss 7.5epss 0.01

    The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to…

  • CVE-2026-6206MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for…

  • CVE-2013-3843Jun 13, 2014
    risk 0.05cvss epss 0.20

    Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.

  • CVE-2013-3724Aug 1, 2013
    risk 0.04cvss epss 0.14

    The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.

  • CVE-2002-2154Dec 31, 2002
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.

  • CVE-2004-0276Nov 23, 2004
    risk 0.03cvss epss 0.04

    The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.

  • CVE-2002-1852Dec 31, 2002
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.

  • CVE-2002-1663Dec 31, 2002
    risk 0.03cvss epss 0.04

    The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.

  • CVE-2025-63650Jan 29, 2026
    risk 0.00cvss epss 0.01

    An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63655Jan 29, 2026
    risk 0.00cvss epss 0.07

    A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63653Jan 29, 2026
    risk 0.00cvss epss 0.01

    An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63652Jan 29, 2026
    risk 0.00cvss epss 0.01

    A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63658Jan 29, 2026
    risk 0.00cvss epss 0.01

    A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63657Jan 29, 2026
    risk 0.00cvss epss 0.01

    An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63651Jan 29, 2026
    risk 0.00cvss epss 0.01

    A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

  • CVE-2025-63649Jan 29, 2026
    risk 0.00cvss epss 0.01

    An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted POST request to the server.