| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-22703 | WordPress WCP Contact Form Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS) | Webcodin | WCP Contact Form | High | 7.1 | 2023-05-15 10:28:16 | Deep Dive |
| CVE-2023-23812 | WordPress Enhanced WP Contact Form Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) | Joost de Valk | Enhanced WP Contact Form | Medium | 5.9 | 2023-05-10 07:38:58 | Deep Dive |
| CVE-2022-47608 | WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS) | Fullworks | Quick Contact Form | Medium | 5.9 | 2023-04-25 16:56:57 | Deep Dive |
| CVE-2023-24386 | WordPress AI Contact Us Form Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) | Karishma Arora | AI Contact Us Form | Medium | 5.9 | 2023-04-23 09:38:17 | Deep Dive |
| CVE-2023-1282 | Drag and Drop Multiple File Upload PRO - Reflected Cross-Site Scripting | Unknown | Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard | 中危 | - | 2023-04-17 12:17:42 | Deep Dive |
| CVE-2023-0546 | FluentForms < 4.3.25 - Contributor+ Stored XSS via Custom HTML Form Field | Unknown | Contact Form Plugin | 中危 | - | 2023-04-10 13:18:07 | Deep Dive |
| CVE-2014-125095 | BestWebSoft Contact Form Plugin bws_menu.php bws_add_menu_render cross site scripting | BestWebSoft | Contact Form Plugin | Low | 3.5 | 2023-04-09 05:31:04 | Deep Dive |
| CVE-2012-10010 | BestWebSoft Contact Form contact_form.php cntctfrm_settings_page cross-site request forgery | BestWebSoft | Contact Form | Medium | 4.3 | 2023-04-09 05:31:03 | Deep Dive |
| CVE-2023-23885 | WordPress Quick Contact Form Plugin <= 8.0.3.1 is vulnerable to Cross Site Scripting (XSS) | Fullworks | Quick Contact Form | Medium | 6.5 | 2023-04-07 11:46:31 | Deep Dive |
| CVE-2013-10022 | BestWebSoft Contact Form Plugin contact_form.php cntctfrm_check_form cross site scripting | BestWebSoft | Contact Form Plugin | Low | 3.5 | 2023-04-05 12:31:03 | Deep Dive |
| CVE-2023-0484 | Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks < 1.1.6 - Arbitrary Plugin Activation via CSRF | Unknown | Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks | 中危 | - | 2023-03-27 15:37:28 | Deep Dive |
| CVE-2022-47173 | WordPress Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration Plugin <= 1.62.0 is vulnerable to Cross Site Scripting (XSS) | nasirahmed | Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration | Medium | 5.9 | 2023-03-23 15:57:30 | Deep Dive |
| CVE-2022-47166 | WordPress Void Contact Form 7 Widget For Elementor Page Builder Plugin <= 2.1.1 is vulnerable to Cross Site Request Forgery (CSRF) | voidCoders | Void Contact Form 7 Widget For Elementor Page Builder | Medium | 4.3 | 2023-03-13 09:09:54 | Deep Dive |
| CVE-2020-36670 | NEX-Forms <= 7.7.1 - Missing Authorization on Various AJAX Actions | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | Medium | 6.3 | 2023-03-07 15:34:03 | Deep Dive |
| CVE-2023-0084 | Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | High | 7.2 | 2023-03-02 18:35:22 | Deep Dive |
| CVE-2023-0085 | Metform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection Bypass | roxnor | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Medium | 5.3 | 2023-03-02 16:01:14 | Deep Dive |
| CVE-2023-1112 | Drag and Drop Multiple File Upload Contact Form 7 admin-ajax.php path traversal | - | Drag and Drop Multiple File Upload Contact Form 7 | Medium | 4.7 | 2023-03-01 09:54:39 | Deep Dive |
| CVE-2023-0487 | My Sticky Elements < 2.0.9 - Admin+ SQLi | Unknown | All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs | 高危 | - | 2023-02-27 15:24:40 | Deep Dive |
| CVE-2023-23899 | WordPress Extensions For CF7 Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF) | HasThemes | Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) | Medium | 4.3 | 2023-02-17 14:14:11 | Deep Dive |
| CVE-2023-0143 | Send PDF for Contact Form 7 < 0.9.9.2 - Contributor+ Stored XSS via Shortcode | Unknown | Send PDF for Contact Form 7 | 中危 | - | 2023-02-06 19:59:17 | Deep Dive |