| CVE-2023-0688 | Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf_thankyou shortcode | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 6.5 | 2023-06-09 05:33:23 | Deep Dive |
| CVE-2023-1615 | WordPress Plugin Ultimate Addons for Contact Form SQL注入漏洞 | psdtowpservice | Ultimate Addons for Contact Form 7 | High | 8.8 | 2023-06-09 05:33:22 | Deep Dive |
| CVE-2023-1843 | Metform Elementor Contact Form Builder <= 3.3.0 - Missing Authorization | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 6.5 | 2023-06-09 05:33:19 | Deep Dive |
| CVE-2023-0709 | Metform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf_last_name shortcode | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 5.4 | 2023-06-09 05:33:14 | Deep Dive |
| CVE-2023-0693 | Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via 'mf_transaction_id' shortcode | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 6.5 | 2023-06-09 05:33:13 | Deep Dive |
| CVE-2023-0694 | Metform Elementor Contact Form Builder <= 3.3.1 - Authenticated (Subscriber+) Information Disclosure via mf shortcode | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 6.5 | 2023-06-09 05:33:12 | Deep Dive |
| CVE-2023-0695 | Metform Elementor Contact Form Builder <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via mf shortcode | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 5.4 | 2023-06-09 05:33:12 | Deep Dive |
| CVE-2020-36717 | Kali Forms <= 2.1.1 - Cross-Site Request Forgery | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | High | 8.8 | 2023-06-07 01:51:36 | Deep Dive |
| CVE-2019-25145 | Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection | smub | Contact Form & SMTP Plugin for WordPress by PirateForms | High | 7.2 | 2023-06-07 01:51:34 | Deep Dive |
| CVE-2020-36720 | Kali Forms <= 2.1.1 - Missing Authorization to Settings Update | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | High | 7.1 | 2023-06-07 01:51:34 | Deep Dive |
| CVE-2020-36712 | Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | High | 8.6 | 2023-06-07 01:51:32 | Deep Dive |
| CVE-2023-2301 | Contact Form Builder by vcita <= 4.10.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting | eyale-vc | Contact Form Builder by vcita | Medium | 6.1 | 2023-06-03 04:35:15 | Deep Dive |
| CVE-2023-2302 | Contact Form and Calls To Action by vcita <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | vcita | Contact Form and Calls To Action by vcita | Medium | 6.4 | 2023-06-03 04:35:15 | Deep Dive |
| CVE-2023-2303 | Contact Form and Calls To Action by vcita <= 4.10.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting | eyale-vc | Contact Form Builder by vcita | Medium | 6.1 | 2023-06-03 04:35:14 | Deep Dive |
| CVE-2023-2300 | Contact Form Builder by vcita <= 4.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | eyale-vc | Contact Form Builder by vcita | Medium | 6.4 | 2023-06-03 04:35:13 | Deep Dive |
| CVE-2023-33311 | WordPress Contact Form Entries Plugin <= 1.3.0 is vulnerable to Cross Site Scripting (XSS) | CRM Perks | Contact Form Entries | Medium | 6.5 | 2023-05-28 18:32:38 | Deep Dive |
| CVE-2023-25976 | WordPress Integration for Contact Form 7 and Zoho CRM, Bigin Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) | CRM Perks | Integration for Contact Form 7 and Zoho CRM, Bigin | Medium | 4.3 | 2023-05-26 11:13:08 | Deep Dive |
| CVE-2022-45364 | WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.6.5 is vulnerable to Cross Site Request Forgery (CSRF) | Glen Don L. Mongaya | Drag and Drop Multiple File Upload – Contact Form 7 | Medium | 5.4 | 2023-05-24 15:48:57 | Deep Dive |
| CVE-2023-2528 | Contact Form by Supsystic <= 1.7.24 - Cross-Site Request Forgery via AJAX action | supsysticcom | Contact Form by Supsystic | Medium | 5.4 | 2023-05-16 23:35:31 | Deep Dive |
| CVE-2023-1835 | Ninja Forms < 3.6.22 - Reflected XSS | Unknown | Ninja Forms Contact Form | 中危 | - | 2023-05-15 12:15:46 | Deep Dive |