Bestwebsoft
Bestwebsoft Contact Form: vulnerabilidades y CVE
Bestwebsoft Contact Form tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-2200 | Media (6.1) | 0.50% | — | 9 abr 2024 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and including, 4.2.8 due to insufficient input… |
| CVE-2024-2198 | Media (6.1) | 0.49% | — | 9 abr 2024 | The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_address’ parameter in all versions up to, and including, 4.2.8 due to insufficient input… |
| CVE-2014-125095 | Media (6.1) | 0.55% | — | 9 abr 2023 | A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The… |
| CVE-2012-10010 | Alta (8.8) | 0.36% | — | 9 abr 2023 | A vulnerability was found in BestWebSoft Contact Form 3.21. It has been classified as problematic. This affects the function cntctfrm_settings_page of the file contact_form.php. The manipulation leads to cross-site… |
| CVE-2013-10022 | Media (6.1) | 0.51% | — | 5 abr 2023 | A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file… |
| CVE-2017-20055 | Media (5.4) | 0.83% | — | 16 jun 2022 | A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate… |
| CVE-2013-7481 | Media (6.1) | 0.92% | — | 22 ago 2019 | The contact-form-plugin plugin before 3.3.5 for WordPress has XSS. |
| CVE-2017-18491 | Media (6.1) | 1.5% | — | 13 ago 2019 | The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues. |
| CVE-2016-10869 | Media (6.1) | 0.92% | — | 13 ago 2019 | The contact-form-plugin plugin before 4.0.2 for WordPress has XSS. |
| CVE-2015-9295 | Media (6.1) | 0.92% | — | 13 ago 2019 | The contact-form-plugin plugin before 3.96 for WordPress has XSS. |
| CVE-2013-7475 | Media (6.1) | 0.92% | — | 13 ago 2019 | The contact-form-plugin plugin before 3.52 for WordPress has XSS. |
| CVE-2017-2171 | Media (6.1) | 0.89% | — | 22 may 2017 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to… |