Crmperks
Crmperks CRM Perks Forms: vulnerabilidades y CVE
Crmperks CRM Perks Forms tiene 9 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-57421 | Alta (7.1) | 0.25% | — | 13 jul 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affects CRM Perks Forms: from n/a through… |
| CVE-2024-37463 | Crítica (9.8) | 0.45% | — | 1 nov 2024 | Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5. |
| CVE-2024-7484 | Alta (7.2) | 0.93% | — | 6 ago 2024 | The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it… |
| CVE-2024-30446 | Media (5.4) | 0.34% | — | 29 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4. |
| CVE-2024-30499 | Alta (8.8) | 0.58% | — | 29 mar 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4. |
| CVE-2024-30498 | Crítica (10) | 2.2% | — | 29 mar 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4. |
| CVE-2023-51536 | Media (4.8) | 0.34% | — | 1 feb 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress… |
| CVE-2023-2836 | Media (4.8) | 0.60% | — | 31 may 2023 | The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it… |
| CVE-2022-38467 | Media (6.1) | 0.81% | — | 14 ene 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Crmperks
Database FOR Contact Form 7, Wpforms, Elementor Forms · 4Contact Form Entries · 4Connector FOR Gravity Forms AND Google Sheets · 3Integration FOR Contact Form 7 Hubspot · 3WP Gravity Forms Salesforce · 2WP Gravity Forms Zoho CRM AND Bigin · 2WP Gravity Forms Hubspot · 2Integration FOR Contact Form 7 AND Constant Contact · 2Integration FOR Woocommerce AND Quickbooks · 2Integration FOR Contact Form 7 AND Zoho Crm, Bigin · 2WP Gravity Forms Keap Infusionsoft · 2Integration FOR Contact Form 7 AND Zoho CRM Bigin · 1