| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-5416 | Funnelforms Free <= 3.4 - Missing Authorization to Category Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:32 | Deep Dive |
| CVE-2023-5411 | Funnelforms Free <= 3.4 - Missing Authorization to Post Modification | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:30 | Deep Dive |
| CVE-2023-5382 | Funnelforms Free <= 3.4 - Cross-Site Request Forgery to Arbitrary Post Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 6.5 | 2023-11-22 15:33:28 | Deep Dive |
| CVE-2023-5415 | Funnelforms Free <= 3.4 - Missing Authorization to New Category Creation | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:27 | Deep Dive |
| CVE-2023-5419 | Funnelforms Free <= 3.4 - Missing Authorization to Test Email Sending | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:25 | Deep Dive |
| CVE-2023-5386 | Funnelforms Free <= 3.4 - Missing Authorization to Arbitrary Post Deletion | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 6.5 | 2023-11-22 15:33:23 | Deep Dive |
| CVE-2023-5822 | Drag and Drop Multiple File Upload - Contact Form 7 <= 1.3.7.3 - Unauthenticated Arbitrary File Upload | glenwpcoder | Drag and Drop Multiple File Upload for Contact Form 7 | High | 8.1 | 2023-11-22 15:33:21 | Deep Dive |
| CVE-2023-5417 | Funnelforms Free <= 3.4 - Missing Authorization to Category Update | funnelforms | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free | Medium | 4.3 | 2023-11-22 15:33:20 | Deep Dive |
| CVE-2023-45071 | WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS) | 10Web Form Builder Team | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | High | 7.1 | 2023-10-18 12:38:56 | Deep Dive |
| CVE-2023-45070 | WordPress Form Maker by 10Web Plugin <= 1.15.18 is vulnerable to Cross Site Scripting (XSS) | 10Web Form Builder Team | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | High | 7.1 | 2023-10-18 12:34:30 | Deep Dive |
| CVE-2023-4821 | Drag and Drop Multiple File Upload < 1.1.1 - Unauthenticated Stored Cross-Site Scripting | Unknown | Drag and Drop Multiple File Upload for WooCommerce | 中危 | - | 2023-10-16 19:39:24 | Deep Dive |
| CVE-2023-4950 | Funnelforms Free < 3.4 Unauthenticated Stored Cross-Site Scripting | Unknown | Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor | 中危 | - | 2023-10-16 19:38:58 | Deep Dive |
| CVE-2023-25480 | WordPress Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin <= 1.24.1 is vulnerable to Cross Site Request Forgery (CSRF) | BoldGrid | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | Medium | 4.3 | 2023-10-06 12:41:33 | Deep Dive |
| CVE-2023-44474 | WordPress Tiger Forms Plugin <= 2.0.0 is vulnerable to Cross Site Scripting (XSS) | MD Jakir Hosen | Tiger Forms – Drag and Drop Form Builder | High | 7.1 | 2023-10-02 08:53:04 | Deep Dive |
| CVE-2023-2813 | Multiple Themes - Reflected XSS | Unknown | Aapna | 中危 | - | 2023-09-04 11:27:00 | Deep Dive |
| CVE-2023-37977 | WordPress WPFunnels Plugin <= 2.7.16 is vulnerable to Cross Site Scripting (XSS) | WPFunnels Team | Drag & Drop Sales Funnel Builder for WordPress – WPFunnels | High | 7.1 | 2023-07-27 14:16:11 | Deep Dive |
| CVE-2023-23833 | WordPress Drop Shadow Boxes Plugin <= 1.7.10 is vulnerable to Cross Site Scripting (XSS) | Steven Henty | Drop Shadow Boxes | Medium | 6.5 | 2023-07-25 12:53:42 | Deep Dive |
| CVE-2023-3412 | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Missing Authorization to Stored Cross-Site Scripting | webcraftplugins | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite | Medium | 6.4 | 2023-06-27 03:28:28 | Deep Dive |
| CVE-2023-3411 | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting | webcraftplugins | Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite | Medium | 6.1 | 2023-06-27 03:28:27 | Deep Dive |
| CVE-2023-35095 | WordPress Flo Forms Plugin <= 1.0.40 is vulnerable to Cross Site Scripting (XSS) | Flothemes | Flo Forms – Easy Drag & Drop Form Builder | Medium | 5.9 | 2023-06-20 13:30:02 | Deep Dive |