Infinitumform
Infinitumform GEO Controller: vulnerabilidades y CVE
Infinitumform GEO Controller tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78286 | Crítica (9.8) | 0.56% | — | 27 ago 2026 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. |
| CVE-2025-62109 | Media (5.3) | 0.29% | — | 9 dic 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Controller: from n/a through <= 8.9.4. |
| CVE-2024-7381 | Media (5.3) | 0.34% | — | 5 sept 2024 | The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including,… |
| CVE-2024-7380 | Media (4.3) | 0.26% | — | 5 sept 2024 | The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to,… |
| CVE-2024-3591 | Media (6.5) | 0.49% | — | 1 may 2024 | The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.