| CVE-2024-9891 | Multiline files upload for contact form 7 <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation | zluck | MultiLine Files for Contact Form 7 | Medium | 4.3 | 2024-10-16 02:05:06 | Deep Dive |
| CVE-2024-47331 | WordPress Multi Step for Contact Form plugin <= 2.7.7 - Unauthenticated SQL Injection vulnerability | Ninja Team | Multi Step for Contact Form | Critical | 9.3 | 2024-10-11 18:20:06 | Deep Dive |
| CVE-2024-9507 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder <= 2.15.2 - Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read | bitpressadmin | Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | Medium | 4.9 | 2024-10-11 07:37:46 | Deep Dive |
| CVE-2024-9528 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.9 | 2024-10-05 02:34:50 | Deep Dive |
| CVE-2024-8633 | Form Maker <= 1.15.27 - Authenticated (Administrator+) Stored Cross-Site Scripting | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | Medium | 5.5 | 2024-09-26 11:32:39 | Deep Dive |
| CVE-2024-6517 | Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS | Unknown | Contact Form 7 Math Captcha | - | - | 2024-09-26 06:00:03 | Deep Dive |
| CVE-2024-3866 | Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 4.7 | 2024-09-25 06:49:02 | Deep Dive |
| CVE-2024-7617 | Contact Form to Any API <= 1.2.4 - Unauthenticated Stored Cross-Site Scripting via Contact Form | itpathsolutions | Contact Form to Any API | High | 7.2 | 2024-09-25 02:05:09 | Deep Dive |
| CVE-2024-5053 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.18 - Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.2 | 2024-09-01 10:58:05 | Deep Dive |
| CVE-2024-5857 | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 5.3 | 2024-08-29 03:30:45 | Deep Dive |
| CVE-2024-7447 | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 5.3 | 2024-08-28 11:31:25 | Deep Dive |
| CVE-2024-6311 | Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Upload | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | High | 7.2 | 2024-08-28 06:43:31 | Deep Dive |
| CVE-2024-6312 | Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 6.5 | 2024-08-28 06:43:30 | Deep Dive |
| CVE-2024-6568 | Flamix: Bitrix24 and Contact Form 7 integrations <= 3.1.0 - Unauthenticated Full Path Disclosure | flamix | Flamix: Bitrix24 and Contact Form 7 integrations | Medium | 5.3 | 2024-08-21 05:30:25 | Deep Dive |
| CVE-2024-7780 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 7.2 | 2024-08-20 03:21:11 | Deep Dive |
| CVE-2024-7782 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 8.7 | 2024-08-20 03:21:11 | Deep Dive |
| CVE-2024-7777 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary File Read And Deletion | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Critical | 9.0 | 2024-08-20 03:21:09 | Deep Dive |
| CVE-2024-7702 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection via getLogHistory Function | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 7.2 | 2024-08-20 03:21:08 | Deep Dive |
| CVE-2024-7775 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary JavaScript File Uploads | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Medium | 5.5 | 2024-08-20 03:21:08 | Deep Dive |
| CVE-2024-43291 | WordPress Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability | voidCoders | Void Contact Form 7 Widget For Elementor Page Builder | Medium | 5.9 | 2024-08-18 21:13:32 | Deep Dive |