Cformsii Project
Cformsii Project Cformsii: vulnerabilidades y CVE
Cformsii Project Cformsii tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-52203 | Media (4.8) | 0.32% | — | 8 ene 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. |
| CVE-2023-25449 | Alta (8.8) | 0.27% | — | 15 jun 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. |
| CVE-2014-10393 | Media (6.1) | 0.91% | — | 22 ago 2019 | The cforms2 plugin before 10.5 for WordPress has XSS. |
| CVE-2014-10392 | Media (6.1) | 0.93% | — | 22 ago 2019 | The cforms2 plugin before 10.2 for WordPress has XSS. |
| CVE-2017-18570 | Crítica (9.8) | 1.8% | — | 22 ago 2019 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. |
| CVE-2015-9333 | Crítica (9.8) | 1.8% | — | 22 ago 2019 | The cforms2 plugin before 14.6.10 for WordPress has SQL injection. |
| CVE-2017-18559 | Media (6.1) | 0.92% | — | 21 ago 2019 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. |
| CVE-2014-10377 | Media (6.1) | 0.93% | — | 21 ago 2019 | The cforms2 plugin before 13.2 for WordPress has XSS in lib_ajax.php. |
| CVE-2019-15238 | Alta (8.8) | 0.74% | — | 20 ago 2019 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. |