Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-52203 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2023-25449 | Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2017-18570 | The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2017-18559 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2019-15238 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |