| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2021-24689 | Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File Read | Unknown | Contact Forms – Drag & Drop Contact Form Builder | 中危 | - | 2022-02-28 09:06:04 | Deep Dive |
| CVE-2021-24688 | Orange Form <= 1.0.1 - Unauthenticated Arbitrary Post Deletion | Unknown | Orange Form | 中危 | - | 2022-02-28 09:06:02 | Deep Dive |
| CVE-2021-24867 | Backdoored Plugins & Themes from AccessPress Themes | AccessPress Themes | Frontend Post WordPress Plugin – AccessPress Anonymous Post | 超危 | - | 2022-02-21 10:45:39 | Deep Dive |
| CVE-2021-25107 | Form Store to DB < 1.1.1 - Unauthenticated Stored Cross-Site Scripting | Unknown | Form Store to DB | 中危 | - | 2022-02-14 09:20:51 | Deep Dive |
| CVE-2022-0148 | All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS) | Unknown | All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements | 中危 | - | 2022-02-07 15:47:25 | Deep Dive |
| CVE-2021-25063 | Contact Form 7 Skins < 2.5.1 - Reflected Cross-Site Scripting (XSS) | Unknown | Skins for Contact Form 7 | 中危 | - | 2022-02-01 12:21:35 | Deep Dive |
| CVE-2022-23598 | Reflected XSS vulnerability when rendering error messages in laminas-form | laminas | laminas-form | Medium | 6.1 | 2022-01-28 22:00:16 | Deep Dive |
| CVE-2021-25080 | Contact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site Scripting | Unknown | Contact Form Entries – Contact Form 7, WPforms and more | 中危 | - | 2022-01-24 08:01:28 | Deep Dive |
| CVE-2021-25079 | Contact Form Entries < 1.2.4 - Reflected Cross-Site Scripting | Unknown | Contact Form Entries – Contact Form 7, WPforms and more | 中危 | - | 2022-01-24 08:01:27 | Deep Dive |
| CVE-2021-24967 | Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting | Unknown | Contact Form & Lead Form Elementor Builder | 中危 | - | 2021-12-27 10:33:21 | Deep Dive |
| CVE-2021-36886 | WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.9 - Cross-Site Request Forgery (CSRF) vulnerability | CipherCoin | Contact Form 7 Database Addon – CFDB7 (WordPress plugin) | Medium | 6.5 | 2021-12-22 18:06:47 | Deep Dive |
| CVE-2021-36885 | WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability | CipherCoin | Contact Form 7 Database Addon – CFDB7 (WordPress plugin) | Medium | 6.1 | 2021-12-22 18:06:39 | Deep Dive |
| CVE-2021-24907 | Everest Forms < 1.8.0 - Reflected Cross-Site Scripting | Unknown | Contact Form, Drag and Drop Form Builder for WordPress – Everest Forms | 中危 | - | 2021-12-21 08:45:34 | Deep Dive |
| CVE-2021-24955 | ProfilePress < 3.2.3 - Reflected Cross-Site Scripting | Unknown | User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar) | 中危 | - | 2021-12-13 10:41:29 | Deep Dive |
| CVE-2021-24954 | ProfilePress < 3.2.3 - Reflected Cross-Site Scripting | Unknown | User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar) | 中危 | - | 2021-12-13 10:41:28 | Deep Dive |
| CVE-2021-24790 | Contact Form Advanced Database <= 1.0.8 - Unauthorised AJAX Calls | Unknown | Contact Form Advanced Database | 中危 | - | 2021-12-13 10:40:54 | Deep Dive |
| CVE-2021-24718 | ARForms Form Builder < 1.5 - Admin+ Stored Cross Site Scripting | Unknown | Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder | 中危 | - | 2021-12-06 15:55:24 | Deep Dive |
| CVE-2021-42358 | Contact Form With Captcha <= 1.6.2 Cross-Site Request Forgery to Reflected Cross-Site Scripting | Contact Form With Captcha | Contact Form With Captcha | High | 8.8 | 2021-11-29 18:10:18 | Deep Dive |
| CVE-2021-24889 | Ninja Forms < 3.6.4 - Admin+ SQL Injection | Unknown | Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress | 高危 | - | 2021-11-29 08:25:45 | Deep Dive |
| CVE-2021-24700 | Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting | Unknown | Forminator – Contact Form, Payment Form & Custom Form Builder | 中危 | - | 2021-11-23 19:16:06 | Deep Dive |