Skip to main content

Vendor archive

formtools CVEs

Beta · best-effort

13 CVEs tagged to vendor formtools2 Critical, 2 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2024-6937

Published Jul 21, 2024

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.ph…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6936

Published Jul 21, 2024

A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/inde…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6935

Published Jul 21, 2024

A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User Se…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6934

Published Jul 21, 2024

A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part of the file /admin/forms/add/step2.php?submission_type=dir…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22722

Published Apr 11, 2024

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the appl…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22721

Published Apr 11, 2024

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22719

Published Apr 11, 2024

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22718

Published Apr 11, 2024

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-22717

Published Apr 11, 2024

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22637

Published Jan 25, 2024

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38145

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-38144

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a form via the submission_id parameter, e.g., clients/forms/ed…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38143

Published Aug 31, 2021

An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1