Skip to main content

Vendor/product archive

formtools / form_tools CVEs

Beta · best-effort

10 CVEs tagged to formtools / form_tools1 Critical, 2 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2024-6937

Published Jul 21, 2024

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.ph…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6936

Published Jul 21, 2024

A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/inde…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6935

Published Jul 21, 2024

A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User Se…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6934

Published Jul 21, 2024

A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part of the file /admin/forms/add/step2.php?submission_type=dir…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22722

Published Apr 11, 2024

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the appl…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22721

Published Apr 11, 2024

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22719

Published Apr 11, 2024

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22718

Published Apr 11, 2024

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-22717

Published Apr 11, 2024

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22637

Published Jan 25, 2024

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1