Rednao
Rednao Smart Forms: vulnerabilidades y CVE
Rednao Smart Forms tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2022 | Media (4.3) | 0.26% | — | 14 feb 2026 | The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.99.… |
| CVE-2025-5055 | Media (4.4) | 0.29% | — | 24 may 2025 | The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.98 due to insufficient input… |
| CVE-2023-49856 | Alta (8.8) | 0.54% | — | 9 dic 2024 | Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through <= 2.6.84. |
| CVE-2024-33593 | Media (4.3) | 0.34% | — | 29 abr 2024 | Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91. |
| CVE-2024-1905 | Media (5.9) | 0.47% | — | 29 abr 2024 | The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-1307 | Media (6.5) | 0.53% | — | 15 abr 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow users with a role as low as a subscriber to call them and perform unauthorized actions |
| CVE-2024-1306 | Media (5.4) | 0.23% | — | 15 abr 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we… |
| CVE-2023-7203 | Media (6.1) | 0.22% | — | 27 feb 2024 | The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perform unauthorised actions such as deleting… |
| CVE-2022-0163 | Media (6.5) | 0.99% | — | 7 mar 2022 | The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data,… |
| CVE-2019-5924 | Alta (8.8) | 1.2% | — | 12 mar 2019 | Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page. |