| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2023-7288 | Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'update_profile_preference' | paytiumsupport | Paytium: Mollie payment forms & donations | Medium | 5.4 | 2024-10-16 06:43:26 | Deep Dive |
| CVE-2023-7287 | Paytium: Mollie payment forms & donations <= 4.3.7 - Missing Authorization in 'pt_cancel_subscription' | paytiumsupport | Paytium: Mollie payment forms & donations | Medium | 5.4 | 2024-10-16 06:43:24 | Deep Dive |
| CVE-2024-7489 | Forms for Mailchimp by Optin Cat <= 2.5.7 - Authenticated (Editor+) Stored Cross-Site Scripting via Form Color Parameters | fatcatapps | Forms for Mailchimp by Optin Cat – Grow Your MailChimp List | Medium | 4.4 | 2024-10-12 05:39:41 | Deep Dive |
| CVE-2024-8477 | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cross-Site Request Forgery | neeraj_slit | Brevo – Email, SMS, Web Push, Chat, and more. | Medium | 4.3 | 2024-10-10 02:06:12 | Deep Dive |
| CVE-2024-47300 | WordPress CubeWP Forms plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability | Imran Tauqeer | CubeWP Forms | High | 7.1 | 2024-10-06 11:38:29 | Deep Dive |
| CVE-2024-47389 | WordPress NEX-Forms plugin <= 8.7.3 - Reflected Cross Site Scripting (XSS) vulnerability | Basix | NEX-Forms | High | 7.1 | 2024-10-05 14:47:12 | Deep Dive |
| CVE-2024-47393 | WordPress Quill Forms plugin <= 3.7.0 - Cross Site Scripting (XSS) vulnerability | Mohamed Magdy | Quill Forms | Medium | 6.5 | 2024-10-05 14:41:48 | Deep Dive |
| CVE-2024-47624 | WordPress BSK Forms Blacklist plugin <= 3.8.1 - Reflected Cross Site Scripting (XSS) vulnerability | bannersky | BSK Forms Blacklist | High | 7.1 | 2024-10-05 14:29:44 | Deep Dive |
| CVE-2024-47633 | WordPress Zoho forms plugin <= 4.0 - Cross Site Scripting (XSS) vulnerability | Zoho Forms | Zoho Forms | Medium | 6.5 | 2024-10-05 13:08:36 | Deep Dive |
| CVE-2024-47642 | WordPress Keap Official Opt-in Forms plugin <= 2.0.3 - Cross Site Scripting (XSS) vulnerability | Keap | Keap Official Opt-in Forms | Medium | 6.5 | 2024-10-05 12:59:50 | Deep Dive |
| CVE-2024-9528 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - Authenticated (Form Manager+) Stored Cross-Site Scripting | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 4.9 | 2024-10-05 02:34:50 | Deep Dive |
| CVE-2024-8718 | Gravity Forms Toolbar <= 1.7.0 - Reflected Cross-Site Scripting | daveshine | Gravity Forms Toolbar | Medium | 6.1 | 2024-10-01 07:30:11 | Deep Dive |
| CVE-2024-3866 | Ninja Forms Contact Form <= 3.8.15 - Reflected Self-Based Cross-Site Scripting via Referer | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 4.7 | 2024-09-25 06:49:02 | Deep Dive |
| CVE-2024-43999 | WordPress Ninja Forms plugin <= 3.8.11 - Cross Site Scripting (XSS) vulnerability | Saturday Drive | Ninja Forms | Medium | 5.9 | 2024-09-17 23:14:19 | Deep Dive |
| CVE-2024-8246 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation | themekraft | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | High | 8.8 | 2024-09-14 03:19:27 | Deep Dive |
| CVE-2024-1596 | Ninja Forms File Uploads <= 3.3.16 - Unauthenticated Stored Cross-Site Scripting via File Upload | SaturdayDrive | Ninja Forms - File Uploads | High | 7.2 | 2024-09-07 11:17:03 | Deep Dive |
| CVE-2024-5309 | Form Vibes – Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple Functions | wpvibes | Form Vibes – Database Manager for Forms | Medium | 5.4 | 2024-09-05 08:30:09 | Deep Dive |
| CVE-2024-7691 | Flaming Forms <= 1.0.1 - Unauthenticated Stored XSS | Unknown | Flaming Forms | - | - | 2024-09-02 06:00:04 | Deep Dive |
| CVE-2024-7692 | Flaming Forms <= 1.0.1 - Reflected XSS | Unknown | Flaming Forms | - | - | 2024-09-02 06:00:04 | Deep Dive |