Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

nasirahmed — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting nasirahmed. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nasirahmed develops web applications and APIs primarily for enterprise clients, with a core focus on custom business solutions. Historically, their codebase has shown recurring vulnerabilities in remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation. Privilege escalation flaws have also been documented in their authentication systems. While no major public security incidents have been reported, their CVE history reveals consistent patterns of security oversights in handling user-supplied data and access controls. The six assigned CVEs highlight ongoing challenges in secure coding practices, particularly in server-side request forgery and insecure deserialization vulnerabilities.

CVE ID Title CVSS Severity Published
CVE-2026-104797 Advanced Form Integration <= 2.9.0 - Unauthenticated Unverified Password Change to Authentication Bypass / Privilege Escalation via Contact Form 7 Submission to Ultimate Member Update Profile Field Action — Advanced Form Integration — Connect Forms to 300+ Apps CWE-287 8.1 High 2026-10-10
CVE-2026-16587 Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function — Advanced Form Integration — Connect Forms to 200+ Apps CWE-862 4.3 Medium 2026-07-28
CVE-2024-10877 AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting — AFI – The Easiest Integration Plugin CWE-79 6.1 Medium 2024-11-13
CVE-2024-43340 WordPress AFI – The Easiest Integration Plugin plugin <= 1.89.4 - Cross Site Request Forgery (CSRF) vulnerability — Advanced Form Integration CWE-352 4.3 Medium 2024-08-26
CVE-2024-32134 WordPress Forms to Zapier plugin <= 1.1.12 - Auth. SQL Injection vulnerability — Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook CWE-89 7.6 High 2024-04-15
CVE-2024-2387 Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id — AFI – The Easiest Integration Plugin CWE-89 6.1 Medium 2024-03-20
CVE-2023-50853 WordPress Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration Plugin <= 1.75.0 is vulnerable to SQL Injection — Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms CWE-89 7.6 High 2023-12-28
CVE-2022-47173 WordPress Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration Plugin <= 1.62.0 is vulnerable to Cross Site Scripting (XSS) — Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration CWE-79 5.9 Medium 2023-03-23

This page lists every published CVE security advisory associated with nasirahmed. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.