ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-52203
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.

NVD description · AI analysis pending
4.8<1%
  • cformsii project cformsii
CVE-2023-25449
Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.

Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.

NVD description · AI analysis pending
8.8<1%
  • cformsii project cformsii
CVE-2017-18570
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.

NVD description · AI analysis pending
9.82%
  • cformsii project cformsii
CVE-2017-18559
The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.

The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.

NVD description · AI analysis pending
6.1<1%
  • cformsii project cformsii
CVE-2019-15238
The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.

The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.

NVD description · AI analysis pending
8.8<1% PoC
  • cformsii project cformsii