All 4 CVE vulnerabilities found in Hash Form – Drag & Drop Form Builder, with AI-generated Chinese analysis, references, and POCs.
Vendor: hashthemes
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-12201 | Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creation CWE-862 | 4.3 | Medium | 2024-12-12 |
| CVE-2024-9417 | Hash Form - Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload CWE-434 | 6.1 | Medium | 2024-10-05 |
| CVE-2024-5084 | Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution CWE-434 | 9.8 | Critical | 2024-05-23 |
| CVE-2024-5085 | Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection CWE-502 | 8.1 | High | 2024-05-23 |
All 4 known CVE vulnerabilities affecting Hash Form – Drag & Drop Form Builder with full Chinese analysis, references, and POCs where available.