| CVE-2024-6312 | Funnelforms Free <= 3.7.3.2 - Authenticated (Administrator+) Arbitrary File Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 6.5 | 2024-08-28 06:43:30 | Deep Dive |
| CVE-2024-7780 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 7.2 | 2024-08-20 03:21:11 | Deep Dive |
| CVE-2024-7782 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 8.7 | 2024-08-20 03:21:11 | Deep Dive |
| CVE-2024-7777 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary File Read And Deletion | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Critical | 9.0 | 2024-08-20 03:21:09 | Deep Dive |
| CVE-2024-7775 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) Arbitrary JavaScript File Uploads | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Medium | 5.5 | 2024-08-20 03:21:08 | Deep Dive |
| CVE-2024-7702 | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.9 - Authenticated (Administrator+) SQL Injection via getLogHistory Function | bitpressadmin | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | High | 7.2 | 2024-08-20 03:21:08 | Deep Dive |
| CVE-2024-6123 | Bit Form <= 2.13.3 - Authenticated (Administrator+) Arbitrary File Upload | bitpressadmin | Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | High | 7.2 | 2024-07-09 07:38:45 | Deep Dive |
| CVE-2024-6297 | Several WordPress.org Plugins <= Various Versions - Injected Backdoor | warfareplugins | Social Sharing Plugin – Social Warfare | Critical | 10.0 | 2024-06-25 03:30:38 | Deep Dive |
| CVE-2024-1640 | Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form <= 2.10.1 - Unauthenticated Insecure Direct Object Reference to Form Submission Alteration | bitpressadmin | Bit Form – Custom Contact Form, Multi Step, Conversational Form & Payment Form builder | Medium | 5.3 | 2024-03-13 15:26:47 | Deep Dive |
| CVE-2024-25905 | WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) | Mondula GmbH | Multi Step Form | Medium | 5.4 | 2024-02-21 06:47:54 | Deep Dive |
| CVE-2023-50832 | WordPress Multi Step Form Plugin <= 1.7.13 is vulnerable to Cross Site Scripting (XSS) | Mondula GmbH | Multi Step Form | Medium | 5.9 | 2023-12-21 17:23:06 | Deep Dive |
| CVE-2023-5990 | Funnelforms Free < 3.4.2 - Form Deletion/Duplication via CSRF | Unknown | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor | - | - | 2023-12-04 21:29:11 | Deep Dive |
| CVE-2023-47758 | WordPress Multi Step Form Plugin <= 1.7.11 is vulnerable to Cross Site Request Forgery (CSRF) | Mondula GmbH | Multi Step Form | Medium | 5.4 | 2023-11-22 18:09:52 | Deep Dive |
| CVE-2023-5385 | Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Duplication | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:37 | Deep Dive |
| CVE-2023-5387 | Funnelforms Free <= 3.4 - Missing Authorization to Enable/Disable Dark Mode | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:35 | Deep Dive |
| CVE-2023-5383 | Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Duplication | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:35 | Deep Dive |
| CVE-2023-5416 | Funnelforms Free <= 3.4 - Missing Authorization to Category Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:32 | Deep Dive |
| CVE-2023-5411 | Funnelforms Free <= 3.4 - Missing Authorization to Post Modification | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:30 | Deep Dive |
| CVE-2023-5382 | Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 6.5 | 2023-11-22 15:33:28 | Deep Dive |
| CVE-2023-5415 | Funnelforms Free <= 3.4 - Missing Authorization to New Category Creation | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:27 | Deep Dive |